CVE-2020-29557
dlink dir-825 r1 firmware
Published 29 Jan 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
References
- shaqed.github.io/dlink/ · Broken Link, Exploit, Third Party Advisory
- www.dlink.ru/ru/download2/5/19/2354/441/ · Product
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29557 · US Government Resource