A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an existing lease with a malicious hostname, arbitrary commands can be executed with root privileges.
References
| Link | Resource |
|---|---|
| https://tzh00203.notion.site/D-Link-DIR895LA1-v102b07-Command-Injection-in-DHCPd-2d4b5c52018a80a1a5ccfb317b308861?source=copy_link | Third Party Advisory Exploit |
Configurations
Configuration 1 (hide)
| AND |
|
History
10 Feb 2026, 19:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://tzh00203.notion.site/D-Link-DIR895LA1-v102b07-Command-Injection-in-DHCPd-2d4b5c52018a80a1a5ccfb317b308861?source=copy_linkĀ - Third Party Advisory, Exploit | |
| CPE | cpe:2.3:h:dlink:dir-895la1:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-895la1_firmware:102b07:*:*:*:*:*:*:* |
|
| First Time |
Dlink dir-895la1 Firmware
Dlink dir-895la1 Dlink |
12 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-77 |
09 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-09 17:15
Updated : 2026-02-10 19:48
NVD link : CVE-2025-69542
Mitre link : CVE-2025-69542
CVE.ORG link : CVE-2025-69542
JSON object : View
Products Affected
dlink
- dir-895la1_firmware
- dir-895la1
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
