CNNVD-202511-1848 Information
CNNVD ID
CNNVD-202511-1848
Related CVE
- CNNVD Published: 2025-11-17
Description (Chinese)
D-Link DWR-M920等都是中国友讯(D-Link)公司的一款路由器。 D-Link多款产品存在安全漏洞,该漏洞源于对文件/boafrm/formTracerouteDiagnosticRun中参数host的错误操作,可能导致缓冲区溢出。以下产品及版本受到影响:DWR-M920、DWR-M921、DWR-M960、DIR-822K和DIR-825M 1.01.07版本。
Description (English)
D-Link DWR-M920 is a router for the Chinese company D-Link. There is a safety loophole in multiple D-Link products, which stems from a mishandling of the argument host in document/boafrm/formTraceroute Diagnostic Run, which could lead to a spill out of the buffer zone. The following products and versions were affected: DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M Version 1.0.07.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
友讯
Published
2025-11-17
Last Modified
2026-02-24
References
https://vuldb.com/?id.332645 https://vuldb.com/?submit.691809 https://vuldb.com/?submit.693784 https://vuldb.com/?submit.695424 https://vuldb.com/?submit.693806 https://www.dlink.com/ https://github.com/LX-LX88/cve/issues/12 https://vuldb.com/?ctiid.332645 https://vuldb.com/?submit.691816 https://access.redhat.com/security/cve/cve-2025-13305
Share on: