A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
2025-11-23T13:15:47.500
2025-12-02T03:31:56.703
Analyzed
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | dlink | dir-822k_firmware | 1.00_20250513164613 | Yes |
| Hardware | dlink | dir-822k | - | No |
| Operating System | dlink | dwr-m920_firmware | 1.1.50 | Yes |
| Hardware | dlink | dwr-m920 | b2 | No |