CVE-2025-13305
D-Link DWR-M920/DWR-M921/DWR-M960/DIR-822K/DIR-825M formTracerouteDiagnosticRun buffer overflow
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 3.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DIR-822KD-Link · DIR-825MD-Link · DWR-M920D-Link · DWR-M921D-Link · DWR-M960Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →