Skip to main content

Vendor/product archive

dlink / dir-825 CVEs

Beta · best-effort

20 CVEs tagged to dlink / dir-8254 Critical, 14 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-7069

Published Apr 27, 2026

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manip…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-7068

Published Apr 27, 2026

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer ove…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-10666

Published Sep 18, 2025

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument…

CVSS 7.4 · High
evidence mentions
7
Buzz score
38.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-10034

Published Sep 6, 2025

A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-47035

Published Jan 31, 2023

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29332

Published May 17, 2022

D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP ac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46442

Published Apr 27, 2022

In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration file…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-46441

Published Apr 27, 2022

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29296

Published Aug 10, 2021

Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial of service. The vulnerability could be triggered by sendin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10214

Published Mar 7, 2020

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16920

Published Sep 27, 2019

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
62.0
KEV listed
Showing 1-20 of 20 CVEsPage 1 of 1