cbcvebase.
CVE-2025-13306
published 2025-11-18

CVE-2025-13306: A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file…

low2.1CVSS 4.0
AVNACLATNPRLUINVCLVILVALSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Affected

8 ranges
VendorProductVersion rangeFixed in
d-linkdir-822k
d-linkdir-825m
d-linkdwr-m920
d-linkdwr-m921
dlinkdir-822k_firmware
dlinkdir-825m_firmware
dlinkdwr-m920_firmware
dlinkdwr-m921_firmware