ZeroHour

CVE-2023-25280

KEV PoC moderate

Unauthenticated OS Command Injection in D-Link DIR-820 Router (CVE-2023-25280)

CISA: D-Link DIR-820 Router OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2023-25280 is an unauthenticated OS command injection flaw (CWE-78) in D-Link DIR-820 router firmware DIR820LA1_FW105B03, located in the ping.ccp web interface. A remote attacker with no credentials can send a crafted ping_addr parameter to ping.ccp, causing arbitrary operating-system commands to execute on the router. Successful exploitation escalates privileges to root, giving an attacker full control of the device for use as a botnet node or a foothold into the connected network. Users running the affected D-Link DIR-820 hardware are exposed, and because the product is end-of-life/end-of-service, fixes are not expected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-30, EPSS puts the 30-day exploitation probability at 97.9% (100th percentile), a public proof-of-concept is available, and active botnet campaigns such as RondoDox and Mirai-style campaigns are targeting flaws in this class of IoT devices.

What to do: Per CISA's KEV required action, discontinue use of this end-of-life/end-of-service product — retire or replace the DIR-820, since no patched firmware is expected. If replacement must be delayed, restrict the router's web interface so it is not reachable from the WAN, disable remote management, and monitor for signs of botnet infection such as unusual outbound traffic. When inventorying, verify installed firmware version (affected build: DIR820LA1_FW105B03).

Affected
D-Link DIR-820 (DIR-820L) routerDIR8LA1_FW105B03 firmware (the version named in the advisory; no other version ranges were specified)
Estimated exposure
moderatelikely tens of thousands of internet-exposed units (estimated; no authoritative public scan count for this single end-of-life model) — Estimated from D-Link's large consumer-router install base and the typical internet-exposed population of a single end-of-life consumer SKU that is being actively targeted by botnets, rather than from a specific scan count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CISA Known Exploited Vulnerability
Affected
D-Link DIR-820 Router
Required action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-820l firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits

Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.

Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.

Palo Alto Unit 42 · 29d agoMalware in the wildCVE-2019-12725CVE-2019-17621CVE-2019-20500+13 CVEs