CVE-2023-25280: D-Link DIR-820 Router OS Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-30. EPSS: 97.9% chance of exploitation in the next 30 days.
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Affected products
- D-Link DIR-820L Firmware: version 1.05b03 only
Published 2023-03-16. Last modified 2026-06-17.