CVE-2025-13304

8.8

D-Link · DWR-M920, DWR-M921, DWR-M960, DWR-M961, and DIR-825M

A buffer overflow vulnerability exists in the diagnostic ping function of multiple D-Link routers, allowing remote attackers to trigger memory corruption via the host argument.

Executive summary

A critical buffer overflow vulnerability in multiple D-Link router models allows remote attackers to execute arbitrary code or cause system instability.

Vulnerability

This flaw involves a buffer overflow triggered by improper input validation within the /boafrm/formPingDiagnosticRun file. While the CVSS vector indicates low privileges are required, the vulnerability is reachable remotely and poses a significant risk to device integrity.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected routing hardware. Given the CVSS score of 8.8, the potential for unauthorized code execution poses severe risks to network confidentiality and availability, potentially allowing attackers to pivot into internal segments or intercept sensitive traffic.

Remediation

Immediate Action: Since a specific patch is not yet confirmed, administrators should restrict access to the web management interface, disable the diagnostic ping feature if possible, or isolate these devices from public-facing networks.

Proactive Monitoring: Monitor network traffic for unusual diagnostic requests or malformed payloads targeting the /boafrm/formPingDiagnosticRun endpoint.

Compensating Controls: Deploy a Web Application Firewall or an Intrusion Prevention System with rules configured to inspect and block suspicious input strings directed at router management endpoints.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the provided GitHub repository reference.

Analyst recommendation

Due to the remote nature of this vulnerability and the confirmed existence of a public proof-of-concept, users must treat this as a high-priority risk. Administrators should immediately audit their network perimeter to identify affected D-Link hardware and apply the strictest possible access controls until an official firmware update from the vendor is verified and deployed.

More D-Link CVEs

Sources

Originally found and disclosed by LX-LX (VulDB User), per the CVE Program record.