Dlink Dir-825M Firmware vulnerabilities
5 known vulnerabilities affecting dlink/dir-825m_firmware.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4
Vulnerabilities
Page 1 of 1
CVE-2025-13306P2HIGHCVSS 8.8v1.1.122025-11-18
CVE-2025-13306 [HIGH] CWE-74 CVE-2025-13306: A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-13305P2CRITICALCVSS 9.8v1.01.072025-11-17
CVE-2025-13305 [CRITICAL] CWE-119 CVE-2025-13305: A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07
A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the pu
nvd
CVE-2026-7289P2HIGHCVSS 8.8v1.1.122026-04-28
CVE-2026-7289 [HIGH] CWE-119 CVE-2026-7289: A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of t
A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
nvd
CVE-2026-7288P2HIGHCVSS 8.8v1.1.122026-04-28
CVE-2026-7288 [HIGH] CWE-119 CVE-2026-7288: A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function su
A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-13304P2HIGHCVSS 8.8v1.01.07v1.1.472025-11-17
CVE-2025-13304 [HIGH] CWE-119 CVE-2025-13304: A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.
A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public a
nvd