CVE-2026-7069
8.0D-Link · DIR-825
A buffer overflow vulnerability in the miniupnpd component of D-Link DIR-825 routers allows local network attackers to potentially achieve memory corruption via the AddPortMapping function.
Executive summary
A buffer overflow vulnerability in the D-Link DIR-825 router, affecting the AddPortMapping function, poses a significant risk of remote code execution for attackers on the local network.
Vulnerability
This is a buffer overflow vulnerability (CWE-120) located in the AddPortMapping function within the miniupnpd component. An attacker with low-level privileges on the local network can trigger memory corruption by manipulating the NewPortMappingDescription argument.
Business impact
Successful exploitation of this buffer overflow could result in unauthorized code execution, leading to a complete compromise of the router. Given the CVSS score of 8.0, this represents a high-severity risk that could allow attackers to intercept traffic, pivot into the internal network, or permanently disrupt connectivity for business operations.
Remediation
Immediate Action: As the affected hardware is no longer supported by the vendor, users should immediately decommission the device or isolate it from the network if an upgrade to a currently supported model is not immediately possible.
Proactive Monitoring: Monitor local network traffic for unusual UPnP requests or unexpected spikes in traffic directed at the router management interface.
Compensating Controls: Disable UPnP globally on the device and implement strict network segmentation to ensure that only trusted devices can access the router management layer.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided in the vulnerability references.
Analyst recommendation
Due to the end-of-life status of the D-Link DIR-825 and the availability of a public proof-of-concept, this vulnerability poses a persistent and unpatchable risk. Organizations must prioritize the replacement of this hardware with modern, supported networking equipment to maintain a secure perimeter and prevent potential unauthorized access to the internal network.
More D-Link CVEs
Sources
Originally found and disclosed by tian (VulDB User), per the CVE Program record.
- VDB-359644 | D-Link DIR-825 miniupnpd upnpsoap.c AddPortMapping buffer overflow Vulnerability database entry
- VDB-359644 | CTI Indicators (IOB, IOC, IOA)
- Submit #798647 | D-Link DIR-825 C1_FW3.00b32 Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com