In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 825
HWDlinkg1Dlink Dir 825 Firmware
OSDlinkall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2020-29557CRITICAL9.8⚠ KEVPL ✓same product
Buffer overflow w D-Link DIR-825 umożliwiający RCE bez uwierzytelnienia
CVE-2019-16920CRITICAL9.8⚠ KEVPL ✓same product
D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI
CVE-2022-47035CRITICAL9.8PL ✓same product
Buffer Overflow w D-Link DIR-825 umożliwiający zdalne wykonanie kodu
CVE-2026-7068HIGH7.4same product
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file s...
CVE-2026-7069HIGH7.3same product
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping ...