CVE-2023-25279

CRITICAL

D-Link DIR-820L Firmware - OS Command Injection via tools_AccountName

Title source: llm
STIX 2.1

Description

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

Scores

CVSS v3 9.8
EPSS 0.4387
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
dlink/dir-820l_firmware 1.05b03
Published Mar 13, 2023
Tracked Since Feb 18, 2026