Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hx88-32mr-g2vv

Опубликовано: 18 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

EPSS

Процентиль: 28%
0.00102
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-78

Связанные уязвимости

CVSS3: 6.3
nvd
3 месяца назад

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

CVSS3: 6.3
fstec
3 месяца назад

Уязвимость встроенного веб-сервера boa микропрограммного обеспечения маршрутизаторов D-Link DWR-M920, DWR-M921, DIR-822K и DIR-825M, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 28%
0.00102
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-78