Unauthenticated root command injection in fileaccess.cgi on end-of-life D-Link DIR-868L routers (CVE-2025-55583)
Shadowserver honeypots recorded exploitation as of 2026-08-25 and Fortinet ties the flaw to an active Linux botnet, so exposed DIR-868L units left online will be conscripted with no patch ever coming.
The /dws/api/UploadFile endpoint in fileaccess.cgi passes the pre_api_arg parameter straight to shell execution without authentication or sanitization, letting a remote attacker run arbitrary commands as root with a crafted HTTP request. The affected models are end-of-life and will not receive a firmware fix.
Affected: D-Link DIR-868L H/W Rev. Bx firmware FW2.05WWB02; D-Link DIR-860L / DIR-865L / DIR-880L (all models, all hardware revisions, EoL)
How to Test
Identify any DIR-868L (or DIR-860L/865L/880L) units on your network and check for firmware FW2.05WWB02; verify whether the web interface's /dws/api/UploadFile endpoint is reachable from the WAN, and review device behavior for signs of botnet compromise (unexpected outbound traffic, unknown processes).
How to Mitigate
No patch exists — D-Link advisory SAP10397 states these models are End-of-Life/End-of-Service and recommends retiring and replacing them; until replacement, take the device offline or at minimum block all WAN access to its web management interface.