EXPOSURES › CVE-2020-29557
CVE-2020-29557
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DIR-825 R1 devices have an unpatched buffer overflow in their web interface allowing remote code execution.
The buffer overflow vulnerability in the DIR-825 R1 web interface enables remote code execution, allowing attackers to compromise the device and potentially use it as a foothold for broader network attacks. DIB organizations must ensure all network hardware is patched and monitored, as unpatched vulnerabilities in edge devices like routers can lead to supply-chain compromises and data breaches. Organizations should verify vendor patching timelines and consider replacing hardware with a history of critical, unpatched flaws.
Shame score — D-Link has a documented pattern of shipping devices with critical, unpatched vulnerabilities that are actively exploited in the wild, indicating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.