An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 825
HWDlinkr1Dlink Dir 825\/a
HWDlinkd1aDlink Dir 825\/ac
HWDlinkee1aDlink Dir 825\/acf
HWDlinkf1Dlink Dir 825\/gf
HWDlinkgfDlink Dir 825 R1 Firmware
OSDlink≤ 3.0.1
CISA KEV — detailsi
- Vendori
- D-Link
- Producti
- DIR-825 R1 Devices
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Apply updates per vendor instructions.
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
Related vulnerabilities
D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI
Buffer Overflow w D-Link DIR-825 umożliwiający zdalne wykonanie kodu
Auth Bypass w D-Link DIR-825 G1 — nieautoryzowany dostęp do firmware i konfiguracji
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file s...
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping ...