nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-29557 CVE-2020-29557
CRITICALCISA KEV
D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
Record summary
CVE-2020-29557 has a selected CVSS score of 9.8 (critical). CISA lists CVE-2020-29557 in KEV.
Description
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Jun 1, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DIR-825 R1 DevicesBrowse D-Link / DIR-825 R1 Devices | CISA | Version data not supplied | |
References
4shaqed.github.io
https://shaqed.github.io/dlink cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29557 dlink.ru
https://www.dlink.ru/ru/download2/5/19/2354/441