CRITICAL

CVE-2023-25280

Dlink Dir 820l Firmware 2023-03-16 CVSS v3.1
CVSS
9.8
KEV

Description

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

Summary dbcve.org

OS command injection vulnerability in D-Link DIR820LA1 router firmware FW105B03. The ping_addr parameter in ping.ccp lacks proper input sanitization, allowing unauthenticated attackers to inject arbitrary OS commands and escalate privileges to root.

Mitigation

Apply available firmware patch; if no patch exists, disable remote management interface or isolate device behind firewall to reduce attack surface.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

97.86%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE