NJRAT – Active IOCs
July 16, 2025Multiple Microsoft Products Vulnerabilities
July 16, 2025NJRAT – Active IOCs
July 16, 2025Multiple Microsoft Products Vulnerabilities
July 16, 2025Severity
High
Analysis Summary
CVE-2025-7553 CVSS:5.8
A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time Page. The manipulation of the argument NTP Server leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-7603 CVSS:8.3
A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-7602 CVSS:8.3
A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Impact
- Gain Access
- Buffer Overflow
Indicators of Compromise
CVE
CVE-2025-7553
CVE-2025-7603
CVE-2025-7602
Affected Vendors
- D-Link
Affected Products
- D-Link DIR-818LW
- D-Link DI-8100 16.07.26A1
Remediation
Refer to D-Link Website for patch, upgrade, or suggested workaround information.