# CVE-2025-60344

## Summary

- **CVE ID:** CVE-2025-60344
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-24
- **Published:** Oct 21, 2025
- **Last Modified:** Mar 12, 2026

## Description

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

## Affected Products

- D-Link — DSR-150 (1.09B32_WW)

## References

- [CNA](https://github.com/fyoozr/D-Link-DSR-N250-LFI-Vulnerability/)
- [CNA](https://github.com/fyoozr/vulnerability-research/tree/main/CVE-2025-60344)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 10.18%
- **EPSS Percentile:** 95.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._