← Vulnerability feed

Vulnerability record · CVE-2023-25280 · published 16 March 2023

CVE-2023-25280: D-Link DIR-820L ping.ccp OS Command Injection

Dlink · Dir 820l Firmware

The D-Link DIR-820L router firmware (DIR820LA1_FW105B03) fails to sanitize the ping_addr parameter passed to ping.ccp, allowing OS command injection. Because the flaw is remotely reachable without authentication, it exposes the router to full compromise, and the product is end-of-life with no fix expected.

9.8 CVSS 3.1 Critical CISA KEV since 30 Sep 2024 EPSS 98% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote root command injection, KEV-listed with a public exploit and near-maximum EPSS, on an end-of-life device with no patch.

What it is

The D-Link DIR-820L router firmware (DIR820LA1_FW105B03) fails to sanitize the ping_addr parameter passed to ping.ccp, allowing OS command injection. Because the flaw is remotely reachable without authentication, it exposes the router to full compromise, and the product is end-of-life with no fix expected.

Impact

An attacker can execute arbitrary commands as root on the device, gaining full control of the router. That enables traffic interception, credential theft, and use of the device as a persistent foothold in the network.

Attack surface

Reachable over the network via the ping.ccp endpoint with a crafted ping_addr parameter; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the vector (PR:N).

Exploitation

It is listed in CISA KEV (added 2024-09-30) and has a public exploit reference, and EPSS is 0.97864 (99.9th percentile), indicating active exploitation is expected.

What to do

  • Discontinue use of the D-Link DIR-820L; CISA's required action is to stop using the end-of-life product.
  • Replace affected routers with a supported model that receives security updates.
  • If the device cannot be removed immediately, isolate it on a separate network segment and block management/HTTP access from untrusted networks.
  • Restrict remote access to the router's web interface and disable WAN-side administration where possible.
  • Monitor for exploitation attempts against ping.ccp and treat any such device as compromised.

Detection

  • Inspect HTTP requests to ping.ccp for command-injection characters or shell metacharacters in the ping_addr parameter.
  • Monitor router logs and outbound traffic for unexpected command execution or connections from the device.
  • Watch for anomalous processes or shell activity on the router if host-level visibility is available.
  • Alert on any external access to the router's management interface from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-25280 to the Known Exploited Vulnerabilities catalog on 30 September 2024 as "D-Link DIR-820 Router OS Command Injection Vulnerability". Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Federal deadline 21 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25280 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26258D-Link DIR-820L router OS command injection via HTTP POSTD-Link DIR-820L firmware 1.05B03 contains an OS command injection flaw reachable through an HTTP POST request to the set ccp handler, allowing remote…KEVEPSS 92%analysed9.8CVE-2021-45382D-Link DIR series routers command injection in DDNS functionAn OS command injection flaw exists in the DDNS function of the ncc2 binary on multiple D-Link DIR router models (DIR-810L, DIR-820L/LW, DIR-826L, DI…KEVEPSS 98%analysed9.8CVE-2015-1187D-Link and TRENDnet ping tool command injection allows remote code executionThe ping tool in multiple D-Link and TRENDnet router and access point firmware fails to properly authenticate or sanitize the ping_addr parameter pas…KEVEPSS 83%analysed9.8CVE-2024-48150Dlink dir-820l firmware classic buffer overflow vulnerabilityD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.EPSS 0.71%9.8CVE-2023-44808Dlink dir-820l firmware out-of-bounds write vulnerabilityD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.EPSS 0.85%9.8CVE-2023-44809Dlink dir-820l firmware improper privilege management vulnerabilityD-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.EPSS 0.85%9.8CVE-2023-44807Dlink dir-820l firmware out-of-bounds write vulnerabilityD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.EPSS 1.1%9.8CVE-2023-25279Dlink dir-820l firmware os command injection vulnerabilityOS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.EPSS 31%

Source: NIST National Vulnerability Database (record CVE-2023-25280), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.