CVE-2025-52079

8.8

D-Link · DIR-820L

The D-Link DIR-820L router contains an improper access control vulnerability allowing authenticated attackers to modify the administrator password via a crafted POST request.

Executive summary

A critical access control flaw in D-Link DIR-820L firmware allows authenticated attackers to perform unauthorized password changes, potentially leading to full administrative takeover.

Vulnerability

This vulnerability involves improper access control within the administrative password setting function. An authenticated attacker can trigger an unverified password change by sending a specifically crafted POST request to the /get_set.ccp endpoint.

Business impact

The ability for an attacker to modify the administrator password grants them complete control over the affected networking device. This compromise can facilitate unauthorized network traffic interception, configuration changes, and persistent access to the internal network, posing a significant risk to data confidentiality and integrity. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that requires immediate attention from IT security teams.

Remediation

Immediate Action: As no patch is currently confirmed, restrict administrative access to the device to trusted IP addresses only and disable remote management interfaces.

Proactive Monitoring: Review device access logs for unusual POST requests directed at the /get_set.ccp endpoint and monitor for unexpected changes to administrative credentials.

Compensating Controls: Implement network-level segmentation to isolate the router management interface from untrusted segments and utilize a firewall to block unauthorized access to the device administration port.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research repository linked by the CVE record.

Analyst recommendation

Given the potential for total administrative takeover, organizations utilizing the D-Link DIR-820L must treat this vulnerability with high urgency. Even in the absence of a vendor-supplied patch, administrators should immediately implement the recommended compensating controls to minimize the attack surface. Continue to monitor the official D-Link security bulletin for firmware updates and apply them as soon as they become available.

More D-Link CVEs

Sources