Vulnerability record · CVE-2020-29557 · published 29 January 2021
CVE-2020-29557: D-Link DIR-825 R1 web interface buffer overflow
Dlink · Dir 825 R1 Firmware
D-Link DIR-825 R1 devices running firmware through 3.0.1 before 2020-11-20 contain a buffer overflow in the web interface. The flaw allows pre-authentication remote code execution, meaning an attacker can run code on the router without any credentials. Because the device sits at the network edge, compromise gives an attacker a foothold on the internal network.
Description
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication remote code execution on an internet-facing edge device that is in CISA's KEV catalog with a very high EPSS score.
What it is
D-Link DIR-825 R1 devices running firmware through 3.0.1 before 2020-11-20 contain a buffer overflow in the web interface. The flaw allows pre-authentication remote code execution, meaning an attacker can run code on the router without any credentials. Because the device sits at the network edge, compromise gives an attacker a foothold on the internal network.
Impact
An unauthenticated attacker gains remote code execution on the router, allowing full control of the device, interception or redirection of traffic, and use as a pivot into the connected network.
Attack surface
Reachable over the network through the device's web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
CVE-2020-29557 is listed in CISA's Known Exploited Vulnerabilities catalog, and a public exploit reference exists, indicating active exploitation. EPSS gives a 30-day probability of 0.5432 (98.9th percentile), a high likelihood of exploitation activity.
What to do
- Apply the vendor firmware update for DIR-825 R1 (fixed after 2020-11-20) as the first action.
- If the device cannot be patched or is end-of-life, replace it or remove it from the network.
- Disable remote administration of the web interface and restrict management access to trusted internal hosts only.
- Segment or isolate the router from sensitive internal systems until patched.
- Monitor vendor advisories for any further updates to this model.
Detection
- Inspect router and perimeter logs for unusual HTTP requests to the web interface, especially oversized or malformed payloads.
- Alert on unexpected outbound connections or new listening services originating from the router.
- Monitor for configuration changes, new admin accounts, or firmware modifications on the device.
- Watch for the device being used as a pivot, such as scanning or lateral movement sourced from the router's IP.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-29557 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://shaqed.github.io/dlink/ | Broken LinkExploitThird Party Advisory |
| https://www.dlink.ru/ru/download2/5/19/2354/441/ | Product |
| https://shaqed.github.io/dlink/ | Broken LinkExploitThird Party Advisory |
| https://www.dlink.ru/ru/download2/5/19/2354/441/ | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29557 | US Government Resource |
Track CVE-2020-29557 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-29557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.