Daily Wire · Free EditionConfirmed Threats. Zero Noise.

The Exploit Bulletin

What Security Teams Must Act On Today

From the edition of

Wednesday, August 26, 2026

Remote Code ExecutioncriticalCVSS 9.8CVE-2025-55583

Unauthenticated root command injection in fileaccess.cgi on end-of-life D-Link DIR-868L routers (CVE-2025-55583)

Shadowserver honeypots recorded exploitation as of 2026-08-25 and Fortinet ties the flaw to an active Linux botnet, so exposed DIR-868L units left online will be conscripted with no patch ever coming.

The /dws/api/UploadFile endpoint in fileaccess.cgi passes the pre_api_arg parameter straight to shell execution without authentication or sanitization, letting a remote attacker run arbitrary commands as root with a crafted HTTP request. The affected models are end-of-life and will not receive a firmware fix.

Affected: D-Link DIR-868L H/W Rev. Bx firmware FW2.05WWB02; D-Link DIR-860L / DIR-865L / DIR-880L (all models, all hardware revisions, EoL)

How to Test

Identify any DIR-868L (or DIR-860L/865L/880L) units on your network and check for firmware FW2.05WWB02; verify whether the web interface's /dws/api/UploadFile endpoint is reachable from the WAN, and review device behavior for signs of botnet compromise (unexpected outbound traffic, unknown processes).

How to Mitigate

No patch exists — D-Link advisory SAP10397 states these models are End-of-Life/End-of-Service and recommends retiring and replacing them; until replacement, take the device offline or at minimum block all WAN access to its web management interface.