CVE-2020-29557: D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
Other sources
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29557?
CVE-2020-29557 is a buffer overflow vulnerability found in D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.
How severe is CVE-2020-29557?
CVE-2020-29557 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2020-29557?
Attackers can exploit CVE-2020-29557 by leveraging the buffer overflow in the web interface to achieve pre-authentication remote code execution.
Is D-Link DIR-825 R1 firmware version 3.0.1 vulnerable to CVE-2020-29557?
Yes, D-Link DIR-825 R1 firmware version 3.0.1 is vulnerable to CVE-2020-29557.
How do I fix CVE-2020-29557?
To fix CVE-2020-29557, it is advised to update the firmware of the affected D-Link DIR-825 R1 devices to a version beyond 3.0.1 released after 2020-11-20.