Access Control Flaw in D-Link DSL-7740C Maintenance Module
CVE-2025-29520

5.3MEDIUM

Key Information:

Vendor

D-Link

Status
Vendor
CVE Published:
25 August 2025

What is CVE-2025-29520?

A significant access control vulnerability exists in the Maintenance module of the D-Link DSL-7740C router. This flaw allows authenticated attackers with low-level privileges to manipulate high-privileged account passwords, potentially leading to unauthorized privilege escalation. Users of the affected firmware version should update their devices to mitigate this security risk.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.