8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.
AI Analysis
Buffer overflow vulnerability in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K, and DIR-825M via manipulation of the host argument in the /boafrm/formTracerouteDiagnosticRun file, allowing remote exploitation.
Basic Information
ID
CVE-2025-13305
Source
VulDB
Published
Nov 17, 2025 at 23:02
Affected Product
Vendor
D-Link
Product
DWR-M920, DWR-M921, DWR-M960, DIR-822K, DIR-825M
Version
1.01.07
Affected Versions
D-Link DWR-M920 1.01.07
D-Link DWR-M921 1.01.07
D-Link DWR-M960 1.01.07
D-Link DIR-822K 1.01.07
D-Link DIR-825M 1.01.07
D-Link DWR-M921 1.01.07
D-Link DWR-M960 1.01.07
D-Link DIR-822K 1.01.07
D-Link DIR-825M 1.01.07
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
D-Link
Product
DWR-M920, DWR-M921, DWR-M960, DIR-822K, DIR-825M
Version
1.01.07