A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
References
| Link | Resource |
|---|---|
| https://github.com/QIU-DIE/CVE/issues/32 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.333316 | Permissions Required VDB Entry |
| https://vuldb.com/?id.333316 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.693776 | Third Party Advisory VDB Entry |
| https://www.dlink.com/ | Product |
| https://github.com/QIU-DIE/CVE/issues/32 | Exploit Issue Tracking |
Configurations
Configuration 1 (hide)
| AND |
|
History
02 Dec 2025, 03:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/QIU-DIE/CVE/issues/32 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.333316 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.333316 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.693776 - Third Party Advisory, VDB Entry | |
| References | () https://www.dlink.com/ - Product | |
| CPE | cpe:2.3:h:dlink:dir-822k:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-822k_firmware:1.00_20250513164613:*:*:*:*:*:*:* |
|
| First Time |
Dlink
Dlink dir-822k Firmware Dlink dir-822k |
24 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/QIU-DIE/CVE/issues/32 - |
23 Nov 2025, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-23 12:15
Updated : 2025-12-02 03:32
NVD link : CVE-2025-13549
Mitre link : CVE-2025-13549
CVE.ORG link : CVE-2025-13549
JSON object : View
Products Affected
dlink
- dir-822k
- dir-822k_firmware
