PT-2025-47224 · D Link · D-Link Dwr-M921+4

Lx-Lx

·

Published

2025-11-09

·

Updated

2025-12-08

·

CVE-2025-13305

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M version 1.01.07
Description A weakness exists in D-Link routers that involves improper processing of the host argument within the /boafrm/formTracerouteDiagnosticRun file. Manipulation of this argument can lead to a buffer overflow, potentially allowing for remote code execution. The exploit for this issue has been publicly released.
Recommendations Update the firmware on D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M version 1.01.07. If these routers are end-of-life models, consider replacing them to avoid a permanent vulnerability window.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-14557
CVE-2025-13305

Affected Products

D-Link Dir-822
D-Link Dir-825
D-Link Dwr-M920
D-Link Dwr-M921
D-Link Dwr-M960