CVE-2025-13306

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
18/11/2025
Last modified:
18/11/2025

Description

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.