Rewterz
NJRAT – Active IOCs
July 16, 2025
Rewterz
Multiple Microsoft Products Vulnerabilities
July 16, 2025

Multiple D-Link Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2025-7553 CVSS:5.8

A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time Page. The manipulation of the argument NTP Server leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-7603 CVSS:8.3

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7602 CVSS:8.3

A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Impact

  • Gain Access
  • Buffer Overflow

Indicators of Compromise

CVE

  • CVE-2025-7553

  • CVE-2025-7603

  • CVE-2025-7602

Affected Vendors

  • D-Link

Affected Products

  • D-Link DIR-818LW
  • D-Link DI-8100 16.07.26A1

Remediation

Refer to D-Link Website for patch, upgrade, or suggested workaround information.

D-Link Website