{
  "advisories": [
    {
      "id": "EUVD-2025-19207",
      "source": "euvd",
      "title": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device.",
      "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19207"
    }
  ],
  "cve": "CVE-2025-34048",
  "enrichment": {
    "analysis": {
      "en": {
        "generated_at": "2026-04-28T01:18:30.677042+00:00",
        "value": {
          "mitigation_remediation": [
            "Update the firmware of the affected D-Link routers to the latest version that removes the vulnerable getpage parameter in the /cgi-bin/webproc CGI script.",
            "Restrict external access to the router’s web interface by limiting management traffic to trusted internal networks or by applying firewall rules that block WAN or untrusted subnet traffic.",
            "Consider implementing network segmentation to isolate the router from critical internal systems, thereby limiting the impact of any future exploitation."
          ],
          "summary": {
            "action": "Apply Patch",
            "impact": "Arbitrary File Read"
          },
          "threat_synthesis": {
            "affected_systems": "The flaw affects D-Link DSL-2730U, DSL-2750U, and DSL-2750E routers running firmware versions IN_1.02, SEA_1.04, or SEA_1.07. The affected products are commonly used in small‑business and residential environments where the router’s web interface is exposed to WAN or internal networks.",
            "description_and_impact": "The vulnerability is a path traversal flaw in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E routers. An unauthenticated remote attacker can supply crafted requests to the getpage parameter in the /cgi-bin/webproc CGI script, allowing the attacker to read arbitrary files from the device. This can lead to disclosure of sensitive configuration, credentials, or firmware files, thereby compromising confidentiality and potentially enabling further compromise of the network segment the router protects.",
            "risk_and_exploitability": "The CVSS score of 8.7 classifies the issue as high severity, and the EPSS score below 1% indicates that exploitation may currently be uncommon, yet the ability to read arbitrary files without authentication remains a serious threat. The vulnerability is not listed in the CISA KEV catalog, but the existence of publicly available proof‑of‑concept code and documented exploitation suggests that attackers could target vulnerable devices if it remains unpatched. The attack requires network connectivity to the router’s management interface and does not rely on privileged access or knowledge of credentials."
          }
        }
      }
    },
    "created": "2026-04-28T01:30:17.913889+00:00",
    "updated": "2026-04-28T01:30:17.913899+00:00",
    "vendors": []
  },
  "epss": {
    "score": 0.00631
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:d-link:dcs-2750e:sea_1.04:*:*:*:*:*:*:*",
      "cpe:2.3:a:d-link:dcs-2750e:sea_1.07:*:*:*:*:*:*:*",
      "cpe:2.3:h:d-link:dsl-2750u:sea_1.04:*:*:*:*:*:*:*",
      "cpe:2.3:h:d-link:dsl-2750u:sea_1.07:*:*:*:*:*:*:*",
      "cpe:2.3:o:dlink:dsl-2730u_firmware:in_1.02:*:*:*:*:*:*:*"
    ],
    "created": "2025-06-26T15:52:04.200000+00:00",
    "description": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {
        "score": 8.7,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
      }
    },
    "mitre_repo_path": "cves/2025/34xxx/CVE-2025-34048.json",
    "references": [
      "https://github.com/threat9/routersploit/blob/master/routersploit/modules/exploits/routers/dlink/dsl_2730_2750_path_traversal.py",
      "https://vulncheck.com/advisories/dlink-dsl-routers-path-traversal-file-read",
      "https://www.dlink.com",
      "https://www.exploit-db.com/exploits/40735"
    ],
    "title": "D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read",
    "updated": "2026-04-07T14:09:12.488000+00:00",
    "vendors": [
      "d-link",
      "d-link$PRODUCT$dcs-2750e",
      "d-link$PRODUCT$dsl-2750u",
      "dlink",
      "dlink$PRODUCT$dsl-2730u_firmware"
    ],
    "weaknesses": [
      "CWE-22"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2025-06-26T16:15:28.273000+00:00",
    "description": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {
        "score": 8.7,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      }
    },
    "nvd_repo_path": "2025/CVE-2025-34048.json",
    "references": [
      "https://github.com/threat9/routersploit/blob/master/routersploit/modules/exploits/routers/dlink/dsl_2730_2750_path_traversal.py",
      "https://vulncheck.com/advisories/dlink-dsl-routers-path-traversal-file-read",
      "https://www.dlink.com",
      "https://www.exploit-db.com/exploits/40735"
    ],
    "title": null,
    "updated": "2026-06-17T09:13:22.603000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-22"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-06-26T16:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-20",
                "CWE-22"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://github.com/threat9/routersploit/blob/master/routersploit/modules/exploits/routers/dlink/dsl_2730_2750_path_traversal.py",
                "https://vulncheck.com/advisories/dlink-dsl-routers-path-traversal-file-read",
                "https://www.dlink.com",
                "https://www.exploit-db.com/exploits/40735"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV4_0": {
                  "score": 8.7,
                  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "c6de5577-824e-467d-b964-083231380ed1"
      },
      {
        "created": "2025-06-26T18:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "poc",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "5dc4f2ba-28b4-4041-9f3f-cf3690248664"
      },
      {
        "created": "2025-07-16T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "epss": {
                  "new": {
                    "score": 0.00261
                  },
                  "old": {
                    "score": 0.00255
                  }
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "8360724a-99c1-4dca-92cd-a952cec1b658"
      },
      {
        "created": "2025-11-17T21:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
              "old": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device."
            },
            "type": "description"
          }
        ],
        "id": "ad3510a9-b579-49d3-b671-1312e45dec50"
      },
      {
        "created": "2025-11-17T22:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-20"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "e5c36867-b835-4765-b402-f846a448d508"
      },
      {
        "created": "2025-11-21T19:45:00+00:00",
        "data": [
          {
            "details": [
              "d-link",
              "d-link$PRODUCT$dcs-2750e",
              "d-link$PRODUCT$dsl-2750u",
              "dlink",
              "dlink$PRODUCT$dsl-2730u_firmware"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:d-link:dcs-2750e:sea_1.04:*:*:*:*:*:*:*",
                "cpe:2.3:a:d-link:dcs-2750e:sea_1.07:*:*:*:*:*:*:*",
                "cpe:2.3:h:d-link:dsl-2750u:sea_1.04:*:*:*:*:*:*:*",
                "cpe:2.3:h:d-link:dsl-2750u:sea_1.07:*:*:*:*:*:*:*",
                "cpe:2.3:o:dlink:dsl-2730u_firmware:in_1.02:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "d-link",
                "d-link$PRODUCT$dcs-2750e",
                "d-link$PRODUCT$dsl-2750u",
                "dlink",
                "dlink$PRODUCT$dsl-2730u_firmware"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "49d43cf3-657f-4196-84be-464ab97b2445"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:d-link:dcs-2750e:sea_1.04:*:*:*:*:*:*:*",
        "cpe:2.3:a:d-link:dcs-2750e:sea_1.07:*:*:*:*:*:*:*",
        "cpe:2.3:h:d-link:dsl-2750u:sea_1.04:*:*:*:*:*:*:*",
        "cpe:2.3:h:d-link:dsl-2750u:sea_1.07:*:*:*:*:*:*:*",
        "cpe:2.3:o:dlink:dsl-2730u_firmware:in_1.02:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2025-06-26T15:52:04.200000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {},
        "provider": null
      },
      "cvssV4_0": {
        "data": {
          "score": 8.7,
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        "provider": "mitre"
      },
      "epss": {
        "data": {
          "score": 0.00631
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "poc",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://github.com/threat9/routersploit/blob/master/routersploit/modules/exploits/routers/dlink/dsl_2730_2750_path_traversal.py",
        "https://vulncheck.com/advisories/dlink-dsl-routers-path-traversal-file-read",
        "https://www.dlink.com",
        "https://www.exploit-db.com/exploits/40735"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-04-15T00:35:42.020000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "d-link",
        "d-link$PRODUCT$dcs-2750e",
        "d-link$PRODUCT$dsl-2750u",
        "dlink",
        "dlink$PRODUCT$dsl-2730u_firmware"
      ],
      "providers": [
        "mitre"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-22"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-06-26T15:52:04.200000+00:00",
    "description": "A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "poc",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read",
    "updated": "2025-06-26T17:41:34.929000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2025/34xxx/CVE-2025-34048.json",
    "weaknesses": []
  }
}