Description
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2025-11-17: | Advisory disclosed |
| 2025-11-17: | VulDB entry created |
| 2025-11-17: | VulDB entry last update |
Credits
LX-LX (VulDB User)
References
vuldb.com/?id.332646 (VDB-332646 | D-Link DWR-M920/DWR-M921/DIR-822K/DIR-825M formDebugDiagnosticRun system command injection)
vuldb.com/?ctiid.332646 (VDB-332646 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.691813 (Submit #691813 | D-Link DWR-M920 V1.1.5 Command Injection)
vuldb.com/?submit.693805 (Submit #693805 | D-Link DIR-822k TK_1.00_20250513164613 Command Injection (Duplicate))
vuldb.com/?submit.693807 (Submit #693807 | D-Link DWR-M921 V1.1.50 Command Injection (Duplicate))
vuldb.com/?submit.695426 (Submit #695426 | D-Link DIR-825m v1.1.12 Command Injection (Duplicate))
github.com/LX-LX88/cve/issues/15
www.dlink.com/