---
id: CVE-2025-11488
title: A weakness has been identified in D-Link DIR-852 up to 20251002
summary: >-
  A weakness has been identified in D-Link DIR-852 up to 20251002. This affects
  an unknown part of the file /HNAP1/. Executing manipulation can lead to
  command injection. The attack may be launched remotely. The exploit has been
  made avail…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11488'
references:
  - url: 'https://vuldb.com/?ctiid.327605'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327605'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.667505'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/jh0ng/vmpda6/cqi681wr7vci6kx9'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.01631
epssPercentile: 0.75497
ingestedAt: '2026-10-08T13:42:55.013Z'
---

## Overview

A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
