VendorsD-Linkdir-825_firmwareany version
Vulnerabilities

D-Link DIR-825 Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2019-16920
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
Published 2019-09-27 · Analyzed
10.0KEVEPSS 1.000
CVE-2021-46442
In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.
Published 2022-04-27 · Modified
9.8EPSS 0.561
CVE-2025-10666
D-Link DIR-825 apply.cgi sub_4106d4 buffer overflow
Published 2025-09-18 · Modified
9.81 PoCEPSS 0.033
CVE-2022-47035
Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.
Published 2023-01-31 · Modified
9.8EPSS 0.012
CVE-2021-46441
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.
Published 2022-04-27 · Modified
9.0EPSS 0.326
CVE-2024-0717
D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
Published 2024-01-19 · Modified
5.3EPSS 0.182