CVE-2025-15245

A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path traversal. The attack must originate from the local network. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dcs-850l_firmware:1.02.09:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-850l:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-30 11:15

Updated : 2025-12-31 22:12


NVD link : CVE-2025-15245

Mitre link : CVE-2025-15245

CVE.ORG link : CVE-2025-15245


JSON object : View

Products Affected

dlink

  • dcs-850l
  • dcs-850l_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')