ZeroHour

CVE-2020-29557

KEV PoC large

Pre-Authentication Buffer Overflow RCE in D-Link DIR-825 R1 Routers

CISA: D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
54%p99
Published
()
KEV added
AI analysis

CVE-2020-29557 is a critical buffer overflow (CVSS 9.8) in the web interface of D-Link DIR-825 R1 routers running firmware through 3.0.1. Because the flaw is reachable without authentication, a remote attacker can send crafted requests to the router's HTTP management interface and trigger the overflow to execute arbitrary code on the device. Successful exploitation gives the attacker full control of the router, typically enabling traffic interception, further network compromise, or use of the device as an attack pivot or botnet node. Any DIR-825 R1 device whose management interface is reachable — especially units exposed directly to the internet — is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities (added 2021-11-03) and a public proof-of-concept exists, indicating exploitation in the wild.

What to do: Upgrade DIR-825 R1 devices to the fixed firmware released on 2020-11-20 or later, per D-Link's update instructions. Until patched, restrict or disable web-based administration from the WAN side and allow management access only from trusted networks. Given the KEV listing and ~54% EPSS, prioritize internet-facing units and review router logs for signs of compromise.

Affected
D-Link DIR-825 R1 firmwareall versions through 3.0.1 (fixed by vendor update released 2020-11-20)
Estimated exposure
largeon the order of tens of thousands of internet-exposed devices (estimate) — The DIR-825 R1 is a hardware revision of a widely sold consumer router line, and public internet scans of D-Link routers routinely surface tens of thousands of exposed management interfaces, though the exact share for this specific…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.

CISA Known Exploited Vulnerability
Affected
D-Link DIR-825 R1 Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-825 r1 firmware
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news