CVE-2025-13305

A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.
References
Link Resource
https://github.com/LX-LX88/cve/issues/12 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.332645 Permissions Required VDB Entry
https://vuldb.com/?id.332645 Third Party Advisory VDB Entry
https://vuldb.com/?submit.691809 Third Party Advisory VDB Entry
https://vuldb.com/?submit.691816 Third Party Advisory VDB Entry
https://vuldb.com/?submit.693784 Third Party Advisory VDB Entry
https://vuldb.com/?submit.693806 Third Party Advisory VDB Entry
https://vuldb.com/?submit.695424 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
https://github.com/LX-LX88/cve/issues/12 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-825m_firmware:1.01.07:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-825m:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dlink:dwr-m920_firmware:1.01.07:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dwr-m920:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dlink:dwr-m921_firmware:1.01.07:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dwr-m921:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dlink:dwr-m961_firmware:1.01.07:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dwr-m961:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dlink:dwr-m960_firmware:1.01.07:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dwr-m960:b1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-17 23:15

Updated : 2025-12-08 14:35


NVD link : CVE-2025-13305

Mitre link : CVE-2025-13305

CVE.ORG link : CVE-2025-13305


JSON object : View

Products Affected

dlink

  • dwr-m920
  • dwr-m921_firmware
  • dir-825m
  • dwr-m961_firmware
  • dir-825m_firmware
  • dwr-m960_firmware
  • dwr-m921
  • dwr-m960
  • dwr-m920_firmware
  • dwr-m961
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')