CVE-2023-25280
dlink dir820la1_firmware
Published 16 Mar 2023 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 30 Sept 2024, with a remediation deadline of 21 Oct 2024 for US federal agencies.
Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Description
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
References
- github.com/migraine-sudo/D_Link_Vuln/tree/main/cmd%20Inject%20in%20pingV4Msg · Exploit, Third Party Advisory
- www.dlink.com/en/security-bulletin/ · Not Applicable
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-25280 · US Government Resource