CVE 8.7 HIGH

D-Link DWR-M920/DWR-M921/DWR-M960/DIR-822K/DIR-825M formTracerouteDiagnosticRun buffer overflow_CVE-2025-13305

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

AI Analysis

Buffer overflow vulnerability in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K, and DIR-825M via manipulation of the host argument in the /boafrm/formTracerouteDiagnosticRun file, allowing remote exploitation.

Basic Information

ID CVE-2025-13305
Source VulDB
Published Nov 17, 2025 at 23:02

Affected Product

Vendor D-Link
Product DWR-M920, DWR-M921, DWR-M960, DIR-822K, DIR-825M
Version 1.01.07
Affected Versions D-Link DWR-M920 1.01.07
D-Link DWR-M921 1.01.07
D-Link DWR-M960 1.01.07
D-Link DIR-822K 1.01.07
D-Link DIR-825M 1.01.07

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor D-Link
Product DWR-M920, DWR-M921, DWR-M960, DIR-822K, DIR-825M
Version 1.01.07

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.