CVE-2025-13305: D-Link Dir-825m Firmware

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

Affected products

  • D-Link Dir-825m Firmware: version 1.01.07 only
  • D-Link Dwr-m920 Firmware: version 1.01.07 only
  • D-Link Dwr-m921 Firmware: version 1.01.07 only
  • D-Link Dwr-m960 Firmware: version 1.01.07 only
  • D-Link Dwr-m961 Firmware: version 1.01.07 only

Published 2025-11-17. Last modified 2026-06-17.