EXPOSURES › CVE-2023-25280
CVE-2023-25280
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DIR-820 routers allow remote, unauthenticated attackers to escalate privileges to root via OS command injection in the ping_addr parameter.
This unpatched command injection flaw enables remote code execution (RCE) and root escalation on widely deployed D-Link DIR-820 routers, posing a severe supply-chain and network compromise risk for CMMC environments. D-Link has a documented history of similar critical RCE vulnerabilities in consumer firmware, indicating a pattern of negligence in securing network management functions.
Shame score — A critical, actively exploited RCE vulnerability in a widely deployed router product with a history of similar command injection flaws demonstrates a pattern of negligence and inadequate security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.