CRITICAL

CVE-2020-29557

Dlink Dir 825 R1 Firmware 2021-01-29 CVSS v3.1
CVSS
9.8
KEV

Description

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.

Summary dbcve.org

A buffer overflow vulnerability in the web interface of D-Link DIR-825 R1 routers (versions through 3.0.1) allows unauthenticated remote attackers to execute arbitrary code on the device. This pre-authentication RCE requires no user interaction and is exploitable over the network.

Mitigation

Update the DIR-825 R1 firmware to the version released after 2020-11-20. If no update is available, restrict web interface access to trusted networks only or place the device behind a perimeter firewall.

Proof of Concept

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error

EPSS Score

54.32%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE