Medium severity6.3NVD Advisory· Published Nov 18, 2025· Updated Apr 29, 2026
CVE-2025-13306
CVE-2025-13306
Description
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected products
4- cpe:2.3:o:dlink:dir-822k_firmware:tk_1.00_20250513164613:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-825m_firmware:1.1.12:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dwr-m920_firmware:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dwr-m921_firmware:1.1.50:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/LX-LX88/cve/issues/15nvdExploitThird Party AdvisoryIssue Tracking
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- www.dlink.comnvdProduct
News mentions
0No linked articles in our index yet.