Metrics
Affected Vendors & Products
Tue, 18 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dir-822 D-link dir-825 D-link dwr-920 D-link dwr-921 |
|
| Vendors & Products |
D-link
D-link dir-822 D-link dir-825 D-link dwr-920 D-link dwr-921 |
Mon, 17 Nov 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | |
| Title | D-Link DWR-M920/DWR-M921/DIR-822K/DIR-825M formDebugDiagnosticRun system command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-17T23:32:06.249Z
Updated: 2025-11-18T16:36:07.550Z
Reserved: 2025-11-17T14:22:32.469Z
Link: CVE-2025-13306
Updated: 2025-11-18T14:25:28.522Z
Status : Awaiting Analysis
Published: 2025-11-18T00:15:48.380
Modified: 2025-11-18T17:15:59.897
Link: CVE-2025-13306
No data.