Stack-Based Buffer Overflow in D-Link DIR-825 Affected by Remote Exploit
CVE-2025-8949
Key Information:
Badges
What is CVE-2025-8949?
A stack-based buffer overflow vulnerability exists in the D-Link DIR-825 version 2.10, specifically within the get_ping_app_stat function of the ping_response.cgi component. This issue arises from improper handling of the ping_ipaddr argument, allowing attackers to execute remote exploits. As the vulnerability affects products that are no longer supported, it poses a significant risk to users, as malicious actors may leverage this flaw to disrupt services or gain unauthorized access.
Affected Version(s)
DIR-825 2.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved