← Vulnerability feed

Vulnerability record · CVE-2022-47035 · published 31 January 2023

CVE-2022-47035: Dlink dir-825 firmware classic buffer overflow vulnerability

Dlink · Dir 825 Firmware

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

9.8 CVSS 3.1 Critical EPSS 1.2% · top 33.8% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-47035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2021-46442D-Link DIR-825 webupg authentication bypass via autoupgrade.aspThe webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated …EPSS 56%analysed8.9CVE-2025-7206Dlink dir-825 firmware memory buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file swit…EPSS 18%8.8CVE-2021-46441Dlink dir-825 firmware os command injection vulnerabilityIn the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s…EPSS 33%8.8CVE-2020-10213Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …EPSS 5.0%8.8CVE-2020-10214Dlink dir-825 firmware out-of-bounds write vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated …EPSS 18%8.8CVE-2020-10215Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…EPSS 5.3%8.8CVE-2020-10216Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2022-47035), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.