VendorsD-Linkdir-825_firmware2.10
Vulnerabilities

D-Link DIR-825 Firmware 2.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-7206
D-Link DIR-825 httpd switch_language.cgi sub_410DDC stack-based overflow
Published 2025-07-08 · Analyzed
10.0EPSS 0.184
CVE-2025-8949
D-Link DIR-825 httpd ping_response.cgi get_ping_app_stat stack-based overflow
Published 2025-08-14 · Analyzed
9.8EPSS 0.009
CVE-2020-10214
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code via a POST to ntp_sync.cgi with a sufficiently long parameter ntp_server.
Published 2020-03-07 · Modified
9.0EPSS 0.183
CVE-2020-10215
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
Published 2020-03-07 · Modified
9.0EPSS 0.053
CVE-2020-10216
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
Published 2020-03-07 · Modified
9.0EPSS 0.050
CVE-2020-10213
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
Published 2020-03-07 · Modified
9.0EPSS 0.050