CRITICAL
CVE-2023-25280
CVSS
9.8
KEV
Description
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Summary dbcve.org
OS command injection vulnerability in D-Link DIR820LA1 router firmware FW105B03. The ping_addr parameter in ping.ccp lacks proper input sanitization, allowing unauthenticated attackers to inject arbitrary OS commands and escalate privileges to root.
Mitigation
Apply available firmware patch; if no patch exists, disable remote management interface or isolate device behind firewall to reduce attack surface.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
97.86%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.