PT-2025-53716 · D Link · D-Link Dwr-M920

Panda_0X1

·

Published

2025-12-29

·

Updated

2025-12-30

·

CVE-2025-15189

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DWR-M920 versions up to 1.1.50
Description A flaw exists in D-Link DWR-M920. The issue is related to a buffer overflow in the sub 464794 function within the /boafrm/formDefRoute file. Manipulation of the submit-url argument can trigger this overflow, and the attack can be initiated remotely. A publicly available exploit exists.
Recommendations Versions prior to 1.1.50 should be updated.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-15189

Affected Products

D-Link Dwr-M920