PT-2026-35229 · D Link · Dir-825
Tian
·
Published
2026-04-26
·
Updated
2026-04-27
·
CVE-2026-7069
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-825 versions prior to 3.00b32
Description
A buffer overflow exists in the
miniupnpd component within the upnpsoap.c file. The issue occurs in the AddPortMapping() function when it fails to properly validate the size of input data during the copying of the NewPortMappingDescription argument. This flaw allows an attacker on the local network to execute arbitrary code by sending a specially crafted HTTP request. Millions of devices worldwide are potentially affected.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-825