PT-2025-42929 · D Link · Dir-820

Published

2025-10-20

·

Updated

2025-10-22

·

CVE-2025-52079

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-820L version 1.06B02
Description The administrator password setting has improper access control, allowing for unverified password changes via a crafted POST request to the /get set.ccp API endpoint. The request exploits a flaw in how the device handles password modifications. The vulnerable parameter is not explicitly specified.
Recommendations Apply a patch or update to a newer version that addresses this improper access control issue. As a temporary workaround, restrict access to the /get set.ccp API endpoint.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13367
CVE-2025-52079

Affected Products

Dir-820