← Vulnerability feed

Vulnerability record · CVE-2021-46442 · published 27 April 2022

CVE-2021-46442: D-Link DIR-825 webupg authentication bypass via autoupgrade.asp

Dlink · Dir 825 Firmware

The webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated remote attacker can then reach privileged functions such as downloading configuration files and updating firmware. The flaw is rated critical (CVSS 9.8) and a public exploit reference exists.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0%
9.8CVSS 3.1 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated remote access to firmware and configuration functions on an internet-facing edge device, with a public exploit and very high EPSS, makes this an urgent fix.

What it is

The webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated remote attacker can then reach privileged functions such as downloading configuration files and updating firmware. The flaw is rated critical (CVSS 9.8) and a public exploit reference exists.

Impact

An attacker gains unauthenticated access to device administration functions, including configuration file download and firmware update. That exposes stored credentials and network settings and allows persistent control of the router through malicious firmware.

Attack surface

Reachable over the network through the router's web management interface via the autoupgrade.asp endpoint. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.5606 (99th percentile) and the references include a public exploit write-up, so exploitation is feasible and likely. No ransomware association is documented.

What to do

  • Apply the vendor firmware fix from the D-Link security bulletin; if no fix exists for this hardware revision, replace or retire the device.
  • Disable remote/WAN administration of the web interface and restrict management access to a trusted internal network.
  • Change default administrative credentials and any credentials that may have been exposed via configuration download.
  • Monitor the vendor bulletin for updated firmware and re-check the device model and hardware revision against it.

Detection

  • Inspect web server or proxy logs for requests to autoupgrade.asp, especially from untrusted or external source addresses.
  • Alert on firmware update or configuration download activity outside scheduled maintenance windows.
  • Monitor for unexpected configuration changes, new admin accounts, or altered DNS settings on the device.
  • Watch for outbound connections from the router to unknown hosts that could indicate post-exploitation control.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-46442 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2022-47035Dlink dir-825 firmware classic buffer overflow vulnerabilityBuffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method…EPSS 1.2%8.9CVE-2025-7206Dlink dir-825 firmware memory buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file swit…EPSS 18%8.8CVE-2021-46441Dlink dir-825 firmware os command injection vulnerabilityIn the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s…EPSS 33%8.8CVE-2020-10213Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …EPSS 5.0%8.8CVE-2020-10214Dlink dir-825 firmware out-of-bounds write vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated …EPSS 18%8.8CVE-2020-10215Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…EPSS 5.3%8.8CVE-2020-10216Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2021-46442), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.