CRITICAL
CVE-2020-29557
CVSS
9.8
KEV
Description
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
Summary dbcve.org
A buffer overflow vulnerability in the web interface of D-Link DIR-825 R1 routers (versions through 3.0.1) allows unauthenticated remote attackers to execute arbitrary code on the device. This pre-authentication RCE requires no user interaction and is exploitable over the network.
Mitigation
Update the DIR-825 R1 firmware to the version released after 2020-11-20. If no update is available, restrict web interface access to trusted networks only or place the device behind a perimeter firewall.
Weakness (CWE)
CWE-119
Memory Buffer Bounds Error
EPSS Score
54.32%
Probability of exploitation in next 30 days
99th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.