CVE-2026-7069

8.0

D-Link · DIR-825

A buffer overflow vulnerability in the miniupnpd component of D-Link DIR-825 routers allows local network attackers to potentially achieve memory corruption via the AddPortMapping function.

Executive summary

A buffer overflow vulnerability in the D-Link DIR-825 router, affecting the AddPortMapping function, poses a significant risk of remote code execution for attackers on the local network.

Vulnerability

This is a buffer overflow vulnerability (CWE-120) located in the AddPortMapping function within the miniupnpd component. An attacker with low-level privileges on the local network can trigger memory corruption by manipulating the NewPortMappingDescription argument.

Business impact

Successful exploitation of this buffer overflow could result in unauthorized code execution, leading to a complete compromise of the router. Given the CVSS score of 8.0, this represents a high-severity risk that could allow attackers to intercept traffic, pivot into the internal network, or permanently disrupt connectivity for business operations.

Remediation

Immediate Action: As the affected hardware is no longer supported by the vendor, users should immediately decommission the device or isolate it from the network if an upgrade to a currently supported model is not immediately possible.

Proactive Monitoring: Monitor local network traffic for unusual UPnP requests or unexpected spikes in traffic directed at the router management interface.

Compensating Controls: Disable UPnP globally on the device and implement strict network segmentation to ensure that only trusted devices can access the router management layer.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided in the vulnerability references.

Analyst recommendation

Due to the end-of-life status of the D-Link DIR-825 and the availability of a public proof-of-concept, this vulnerability poses a persistent and unpatchable risk. Organizations must prioritize the replacement of this hardware with modern, supported networking equipment to maintain a secure perimeter and prevent potential unauthorized access to the internal network.

More D-Link CVEs

Sources

Originally found and disclosed by tian (VulDB User), per the CVE Program record.