PT-2025-28805 · D Link · D-Link Dir-825

Ic0Rner

·

Published

2025-07-02

·

Updated

2025-07-14

·

CVE-2025-7206

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: D-Link DIR-825 version 2.10
Description: A critical vulnerability exists in the D-Link DIR-825 router. This issue affects the sub 410DDC function within the switch language.cgi file of the httpd component. Manipulation of the Language parameter leads to a stack-based buffer overflow, potentially allowing remote attackers to crash the web interface. The exploit for this vulnerability has been publicly disclosed. Approximately 47,000 instances of this device have been identified online.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-08440
CVE-2025-7206

Affected Products

D-Link Dir-825