Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-14659 Details

Description

A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')[email protected]
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')[email protected]
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')[email protected]

Affected Products

ProductVersions
dlink dir-868l b1 firmware
<= 203b01

CPE

  • cpe:2.3:o:dlink:dir-868l_b1_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
dlink dir-868l b1
All versions

CPE

  • cpe:2.3:h:dlink:dir-868l_b1:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
dlink dir-860l b1 firmware
<= 203b03

CPE

  • cpe:2.3:o:dlink:dir-860l_b1_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
dlink dir-860l b1
All versions

CPE

  • cpe:2.3:h:dlink:dir-860l_b1:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-14659
NVD Published Date:
Dec 14, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]