CRITICAL🇵🇱 Wersja polska

CVE-2022-47035

CVSS 9.8v3.1pub. 2023-01-31upd. 2025-03-27

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 825

    HW
    Dlink
    all versions
  • Dlink Dir 825 Firmware

    OS
    Dlink
    ≤ 1.33.0.44ebdd4-embedded
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2020-29557CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w D-Link DIR-825 umożliwiający RCE bez uwierzytelnienia

CVE-2019-16920CRITICAL9.8⚠ KEVPL ✓same product

D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI

CVE-2021-46442CRITICAL9.8PL ✓same product

Auth Bypass w D-Link DIR-825 G1 — nieautoryzowany dostęp do firmware i konfiguracji

CVE-2026-7068HIGH7.4same product

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file s...

CVE-2026-7069HIGH7.3same product

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping ...