PT-2025-47224 · D Link · D-Link Dwr-M921+4
Lx-Lx
·
Published
2025-11-09
·
Updated
2025-12-08
·
CVE-2025-13305
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M version 1.01.07
Description
A weakness exists in D-Link routers that involves improper processing of the
host argument within the /boafrm/formTracerouteDiagnosticRun file. Manipulation of this argument can lead to a buffer overflow, potentially allowing for remote code execution. The exploit for this issue has been publicly released.Recommendations
Update the firmware on D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M version 1.01.07. If these routers are end-of-life models, consider replacing them to avoid a permanent vulnerability window.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-822
D-Link Dir-825
D-Link Dwr-M920
D-Link Dwr-M921
D-Link Dwr-M960