Critical severity9.8CISA KEVNVD Advisory· Published Mar 16, 2023· Updated Jun 17, 2026
CVE-2023-25280
CVE-2023-25280
Description
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:dlink:dir-820l_firmware:1.05b03:*:*:*:*:*:*:*
- D-Link/DIR820LA1_FW105B03description
Patches
Vulnerability mechanics
References
3- github.com/migraine-sudo/D_Link_Vuln/tree/main/cmd%20Inject%20in%20pingV4MsgnvdExploitThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.dlink.com/en/security-bulletin/nvdNot Applicable
News mentions
1- RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning ExploitsTrend Micro Research · Oct 9, 2025