A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-822k
Dlink dir-822k Firmware
Dlink dwr-m920
Dlink dwr-m920 Firmware
CPEs cpe:2.3:h:dlink:dir-822k:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dwr-m920:b2:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-822k_firmware:1.00_20250513164613:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m920_firmware:1.1.50:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-822k
Dlink dir-822k Firmware
Dlink dwr-m920
Dlink dwr-m920 Firmware

Wed, 26 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-822
D-link dwr-920
Vendors & Products D-link
D-link dir-822
D-link dwr-920

Mon, 24 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 23 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
Title D-Link DIR-822K/DWR-M920 formDdns memory corruption
Weaknesses CWE-119
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-24T16:27:25.254Z

Reserved: 2025-11-22T15:08:42.670Z

Link: CVE-2025-13547

cve-icon Vulnrichment

Updated: 2025-11-24T16:27:14.353Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-23T11:15:45.900

Modified: 2025-12-02T03:32:40.623

Link: CVE-2025-13547

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-26T11:10:43Z

Weaknesses