8.8

CVE-2025-13306

Exploit

D-Link DWR-M920/DWR-M921/DIR-822K/DIR-825M formDebugDiagnosticRun system command injection

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dlink ≫ Dwr-m920 Firmware Version 1.1.5
   Dlink ≫ Dwr-m920 Version b2
Dlink ≫ Dwr-m921 Firmware Version 1.1.50
   Dlink ≫ Dwr-m921 Version -
Dlink ≫ Dir-822k Firmware Version tk_1.00_20250513164613
   Dlink ≫ Dir-822k Version -
Dlink ≫ Dir-825m Firmware Version 1.1.12
   Dlink ≫ Dir-825m Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.25% 0.943
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cna@vuldb.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.dlink.com/
Product
https://vuldb.com/?id.332646
Third Party Advisory
VDB Entry
https://vuldb.com/?ctiid.332646
VDB Entry
Permissions Required
https://vuldb.com/?submit.691813
Third Party Advisory
VDB Entry
https://vuldb.com/?submit.693805
Third Party Advisory
VDB Entry
https://vuldb.com/?submit.693807
Third Party Advisory
VDB Entry
https://vuldb.com/?submit.695426
Third Party Advisory
VDB Entry
https://github.com/LX-LX88/cve/issues/15
Third Party Advisory
Exploit
Issue Tracking