Vulnerability Description
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dwr-M920 Firmware | 1.1.5 |
| Dlink | Dwr-M920 | b2 |
| Dlink | Dwr-M921 Firmware | 1.1.50 |
| Dlink | Dwr-M921 | - |
| Dlink | Dir-822K Firmware | tk_1.00_20250513164613 |
| Dlink | Dir-822K | - |
| Dlink | Dir-825M Firmware | 1.1.12 |
| Dlink | Dir-825M | - |
Related Weaknesses (CWE)
References
- https://github.com/LX-LX88/cve/issues/15ExploitThird Party AdvisoryIssue Tracking
- https://vuldb.com/?ctiid.332646Permissions RequiredVDB Entry
- https://vuldb.com/?id.332646Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.691813Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.693805Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.693807Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.695426Third Party AdvisoryVDB Entry
- https://www.dlink.com/Product
- https://github.com/LX-LX88/cve/issues/15ExploitThird Party AdvisoryIssue Tracking
FAQ
What is CVE-2025-13306?
CVE-2025-13306 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of th...
How severe is CVE-2025-13306?
CVE-2025-13306 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13306?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dwr-M920 Firmware, Dlink Dwr-M920, Dlink Dwr-M921 Firmware, Dlink Dwr-M921, Dlink Dir-822K Firmware.