Showing 3 vulnerabilities on this page for DIR-825 R1 Devices

Signals CISA KEV Ransomware Nuclei
D-Link vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

D-Link DIR-825 R1 Devices Improper Authentication

In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.

Apr 27, 2022
CVSS9.8v3.1EPSS55.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.

CWE-119CWE-120Jan 29, 2021
CVSS9.8v3.1EPSS54.3%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

D-Link DIR-825 R1 Devices Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

CWE-78Mar 7, 2020
CVSS8.8v3.1EPSS5.26%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX