A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
2025-11-23T14:15:45.397
2025-12-02T03:31:48.043
Analyzed
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | dlink | dir-822k_firmware | 1.00_20250513164613 | Yes |
| Hardware | dlink | dir-822k | - | No |
| Operating System | dlink | dwr-m920_firmware | 1.1.50 | Yes |
| Hardware | dlink | dwr-m920 | b2 | No |