CVE-2025-10666

8.8

D-Link · DIR-825

A buffer overflow vulnerability in D-Link DIR-825 routers allows remote attackers to trigger memory corruption via the countdown_time parameter in the apply.cgi endpoint.

Executive summary

The D-Link DIR-825 router contains a critical buffer overflow vulnerability that allows remote attackers to compromise system integrity, though no official patch is available as the product is end of life.

Vulnerability

This is a stack-based buffer overflow occurring within the sub_4106d4 function of the apply.cgi script. An attacker with low-level privileges can supply an excessively long string to the countdown_time parameter to trigger memory corruption.

Business impact

Successful exploitation of this vulnerability allows for remote code execution, which grants an attacker full control over the affected router. Given the CVSS score of 8.8, the potential for total system compromise is significant. Because this device is end of life and unsupported, organizations are at high risk of permanent exposure to exploitation, which could lead to unauthorized network access, data interception, and lateral movement within the internal network.

Remediation

Immediate Action: Since the vendor has confirmed this product is no longer supported and no security patch will be provided, the immediate action is to retire and decommission the affected hardware.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the apply.cgi endpoint and investigate any unexpected router reboots or service instability.

Compensating Controls: If the device cannot be immediately replaced, isolate it on a restricted management VLAN and use a Web Application Firewall or network-based IPS to block malformed HTTP requests containing oversized parameters.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept and exploit entry exist via ExploitDB and the researcher's published GitHub repository.

Analyst recommendation

Due to the lack of vendor support and the availability of public exploit code, this device represents a severe security liability. Immediate replacement of the D-Link DIR-825 with a currently supported, vendor-maintained solution is the only effective way to mitigate this risk. Organizations should prioritize the isolation of any remaining units until they can be fully decommissioned from the network.

More D-Link CVEs

Sources

Originally found and disclosed by panda_0x1 (VulDB User), per the CVE Program record.