CVE-2023-25280
KEV PoC moderateUnauthenticated OS Command Injection in D-Link DIR-820 Router (CVE-2023-25280)
CISA: D-Link DIR-820 Router OS Command Injection Vulnerability
CVE-2023-25280 is an unauthenticated OS command injection flaw (CWE-78) in D-Link DIR-820 router firmware DIR820LA1_FW105B03, located in the ping.ccp web interface. A remote attacker with no credentials can send a crafted ping_addr parameter to ping.ccp, causing arbitrary operating-system commands to execute on the router. Successful exploitation escalates privileges to root, giving an attacker full control of the device for use as a botnet node or a foothold into the connected network. Users running the affected D-Link DIR-820 hardware are exposed, and because the product is end-of-life/end-of-service, fixes are not expected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-30, EPSS puts the 30-day exploitation probability at 97.9% (100th percentile), a public proof-of-concept is available, and active botnet campaigns such as RondoDox and Mirai-style campaigns are targeting flaws in this class of IoT devices.
What to do: Per CISA's KEV required action, discontinue use of this end-of-life/end-of-service product — retire or replace the DIR-820, since no patched firmware is expected. If replacement must be delayed, restrict the router's web interface so it is not reachable from the WAN, disable remote management, and monitor for signs of botnet infection such as unusual outbound traffic. When inventorying, verify installed firmware version (affected build: DIR820LA1_FW105B03).
| D-Link DIR-820 (DIR-820L) router | DIR8LA1_FW105B03 firmware (the version named in the advisory; no other version ranges were specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
- Affected
- D-Link DIR-820 Router
- Required action
- The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dir-820l firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news4 stories
IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.
Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.