HIGH🇬🇧 English

CVE-2026-7069

CVSS 7.3v4.0pub. 2026-04-27upd. 2026-04-30

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

oryginał EN
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dir 825

    HW
    Dlink
    wszystkie wersje
  • Dlink Dir 825 Firmware

    OS
    Dlink
    3.00b32
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Memory
CWE
Referencje

Powiązane podatności

CVE-2020-29557CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Buffer overflow w D-Link DIR-825 umożliwiający RCE bez uwierzytelnienia

CVE-2019-16920CRITICAL9.8⚠ KEVPL ✓ten sam produkt

D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI

CVE-2022-47035CRITICAL9.8PL ✓ten sam produkt

Buffer Overflow w D-Link DIR-825 umożliwiający zdalne wykonanie kodu

CVE-2021-46442CRITICAL9.8PL ✓ten sam produkt

Auth Bypass w D-Link DIR-825 G1 — nieautoryzowany dostęp do firmware i konfiguracji

CVE-2026-7068HIGH7.4ten sam produkt

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file s...