CVE-2025-52079: D-Link DIR-820L Firmware

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.

Affected products

  • D-Link DIR-820L Firmware: version 1.06b02 only

Published 2025-10-21. Last modified 2026-06-17.