A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
| Software | From | Fixed in |
|---|---|---|
| dlink / dwr-m920_firmware | 1.1.5 | 1.1.5.x |
| dlink / dwr-m921_firmware | 1.1.50 | 1.1.50.x |
| dlink / dir-822k_firmware | tk_1.00_20250513164613 | tk_1.00_20250513164613.x |
| dlink / dir-825m_firmware | 1.1.12 | 1.1.12.x |