Vulnerability record · CVE-2021-46442 · published 27 April 2022
CVE-2021-46442: D-Link DIR-825 webupg authentication bypass via autoupgrade.asp
Dlink · Dir 825 Firmware
The webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated remote attacker can then reach privileged functions such as downloading configuration files and updating firmware. The flaw is rated critical (CVSS 9.8) and a public exploit reference exists.
Description
In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote access to firmware and configuration functions on an internet-facing edge device, with a public exploit and very high EPSS, makes this an urgent fix.
What it is
The webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated remote attacker can then reach privileged functions such as downloading configuration files and updating firmware. The flaw is rated critical (CVSS 9.8) and a public exploit reference exists.
Impact
An attacker gains unauthenticated access to device administration functions, including configuration file download and firmware update. That exposes stored credentials and network settings and allows persistent control of the router through malicious firmware.
Attack surface
Reachable over the network through the router's web management interface via the autoupgrade.asp endpoint. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.5606 (99th percentile) and the references include a public exploit write-up, so exploitation is feasible and likely. No ransomware association is documented.
What to do
- Apply the vendor firmware fix from the D-Link security bulletin; if no fix exists for this hardware revision, replace or retire the device.
- Disable remote/WAN administration of the web interface and restrict management access to a trusted internal network.
- Change default administrative credentials and any credentials that may have been exposed via configuration download.
- Monitor the vendor bulletin for updated firmware and re-check the device model and hardware revision against it.
Detection
- Inspect web server or proxy logs for requests to autoupgrade.asp, especially from untrusted or external source addresses.
- Alert on firmware update or configuration download activity outside scheduled maintenance windows.
- Monitor for unexpected configuration changes, new admin accounts, or altered DNS settings on the device.
- Watch for outbound connections from the router to unknown hosts that could indicate post-exploitation control.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/tgp-top/D-Link-DIR-825 | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
| https://github.com/tgp-top/D-Link-DIR-825 | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
Track CVE-2021-46442 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-46442), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.