← Vulnerability feed

Vulnerability record · CVE-2020-29557 · published 29 January 2021

CVE-2020-29557: D-Link DIR-825 R1 web interface buffer overflow

Dlink · Dir 825 R1 Firmware

D-Link DIR-825 R1 devices running firmware through 3.0.1 before 2020-11-20 contain a buffer overflow in the web interface. The flaw allows pre-authentication remote code execution, meaning an attacker can run code on the router without any credentials. Because the device sits at the network edge, compromise gives an attacker a foothold on the internal network.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 54% · top 1.0% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 10.0
54%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityPre-authentication remote code execution on an internet-facing edge device that is in CISA's KEV catalog with a very high EPSS score.

What it is

D-Link DIR-825 R1 devices running firmware through 3.0.1 before 2020-11-20 contain a buffer overflow in the web interface. The flaw allows pre-authentication remote code execution, meaning an attacker can run code on the router without any credentials. Because the device sits at the network edge, compromise gives an attacker a foothold on the internal network.

Impact

An unauthenticated attacker gains remote code execution on the router, allowing full control of the device, interception or redirection of traffic, and use as a pivot into the connected network.

Attack surface

Reachable over the network through the device's web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

CVE-2020-29557 is listed in CISA's Known Exploited Vulnerabilities catalog, and a public exploit reference exists, indicating active exploitation. EPSS gives a 30-day probability of 0.5432 (98.9th percentile), a high likelihood of exploitation activity.

What to do

  • Apply the vendor firmware update for DIR-825 R1 (fixed after 2020-11-20) as the first action.
  • If the device cannot be patched or is end-of-life, replace it or remove it from the network.
  • Disable remote administration of the web interface and restrict management access to trusted internal hosts only.
  • Segment or isolate the router from sensitive internal systems until patched.
  • Monitor vendor advisories for any further updates to this model.

Detection

  • Inspect router and perimeter logs for unusual HTTP requests to the web interface, especially oversized or malformed payloads.
  • Alert on unexpected outbound connections or new listening services originating from the router.
  • Monitor for configuration changes, new admin accounts, or firmware modifications on the device.
  • Watch for the device being used as a pivot, such as scanning or lateral movement sourced from the router's IP.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-29557 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-29557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.8CVE-2026-20700Apple OS memory corruption allows arbitrary code executionA memory corruption flaw caused by improper state management affects iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Apple states it is aware of a re…KEVEPSS 1.3%analysed

Source: NIST National Vulnerability Database (record CVE-2020-29557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.