CVE-2025-8949: D-Link DIR-825 httpd ping_response.cgi get_ping_app_stat stack-based overflow
A vulnerability was identified in D-Link DIR-825 2.10. Affected by this vulnerability is the function getpingappstat of the file pingresponse.cgi of the component httpd. The manipulation of the argument pingipaddr leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8949?
CVE-2025-8949 is classified as a critical vulnerability due to the stack-based buffer overflow it presents.
How do I fix CVE-2025-8949?
To fix CVE-2025-8949, update the D-Link DIR-825 firmware to the latest version provided by D-Link.
What component is affected by CVE-2025-8949?
CVE-2025-8949 affects the httpd component in the D-Link DIR-825, specifically the function get_ping_app_stat.
How can CVE-2025-8949 be exploited?
CVE-2025-8949 can be exploited by manipulating the argument ping_ipaddr, leading to a buffer overflow.
Which devices are impacted by CVE-2025-8949?
The devices impacted by CVE-2025-8949 are D-Link DIR-825 routers running version 2.10.