VYPR
Unrated severityNVD Advisory· Published Nov 17, 2025· Updated Nov 18, 2025

D-Link DWR-M920/DWR-M921/DWR-M960/DWR-M961/DIR-825M formPingDiagnosticRun buffer overflow

CVE-2025-13304

Description

A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

Affected products

8
  • Dlink/DIR-825Mllm-fuzzy
    Range: 1.01.07 / 1.1.47
  • Dlink/DWR-M960llm-fuzzy
    Range: 1.01.07
  • Dlink/DWR-M921llm-fuzzy
    Range: 1.01.07
  • D-Link/DIR-825Mv5
    Range: 1.01.07
  • D-Link/DWR-M920v5
    Range: 1.01.07
  • D-Link/DWR-M921v5
    Range: 1.01.07
  • D-Link/DWR-M960v5
    Range: 1.01.07
  • D-Link/DWR-M961v5
    Range: 1.01.07

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.