CNNVD-202511-1958 Information

CNNVD ID

CNNVD-202511-1958

CVE-2025-13306

  • CNNVD Published: 2025-11-18

Description (Chinese)

D-Link DWR-M920等都是中国友讯(D-Link)公司的一款路由器。 D-Link多款产品存在命令注入漏洞,该漏洞源于对文件/boafrm/formDebugDiagnosticRun中参数host的错误操作,可能导致命令注入。以下产品及版本受到影响:DWR-M920、DWR-M921、DIR-822K和DIR-825M 1.1.5版本。

Description (English)

D-Link DWR-M920 is a router for the Chinese company D-Link. D-Link multi-products have command-injecting holes, which stem from a mishandling of the argument host in file/boafrm/formDebugDiagnosticRun, which may lead to command-injection. The following products and versions were affected: DWR-M920, DWR-M921, DIR-822K and DIR-825M Version 1.1.5.

Hazard Level

High

Vulnerability Type

命令注入

Affected Vendor

友讯

Published

2025-11-18

Last Modified

2026-02-24

References

https://vuldb.com/?id.332646 https://vuldb.com/?submit.695426 https://github.com/LX-LX88/cve/issues/15 https://vuldb.com/?submit.691813 https://vuldb.com/?submit.693807 https://www.dlink.com/ https://vuldb.com/?ctiid.332646 https://vuldb.com/?submit.693805 https://access.redhat.com/security/cve/cve-2025-13306

Share on: