Junglewise Threat Intelligence

CVE-2020-29557: D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

CVE-2020-29557 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: D-Link.

Executive brief

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface. This flaw allows a remote, unauthenticated attacker to achieve code execution on the device.

Affected products

  • D-Link DIR-825 R1 Firmware through 3.0.1 before 2020-11-20
  • D-Link DIR-825 R1
  • D-Link DIR-825/A D1A
  • D-Link DIR-825/AC E1A
  • D-Link DIR-825/AC E
  • D-Link DIR-825/ACF F1
  • D-Link DIR-825/GF GF

Timeline

  • 2020-11-20: patched: Firmware versions before this date are vulnerable.
  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: Reported as exploited in the wild.