CVE-2026-7069
published 2026-04-27CVE-2026-7069: A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component…
PriorityP351high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
1.38%
69.3th percentile
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-825 | — | — |
| dlink | dir-825_firmware | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.7HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
D-Link DIR-825 up to 3.00b32 miniupnpd upnpsoap.c AddPortMapping NewPortMappingDescription buffer overflow (EUVD-2026-25744 / CNNVD-202604-5311)
vuldb·2026-04-29·CVSS 8.6
CVE-2026-7069 [HIGH] D-Link DIR-825 up to 3.00b32 miniupnpd upnpsoap.c AddPortMapping NewPortMappingDescription buffer overflow (EUVD-2026-25744 / CNNVD-202604-5311)
A vulnerability marked as critical has been reported in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2026-7069. The attack needs to be approached within the local network. In addition, an exploit is available.
GHSA
GHSA-2px7-g5g7-9jfm: A security flaw has been discovered in D-Link DIR-825 up to 3
ghsa_unreviewed·2026-04-27
CVE-2026-7069 [HIGH] CWE-119 GHSA-2px7-g5g7-9jfm: A security flaw has been discovered in D-Link DIR-825 up to 3
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
No detection rules found.
No public exploits indexed.
2026-04-27
Published