← Vulnerability feed

Vulnerability record · CVE-2025-52079 · published 21 October 2025

CVE-2025-52079: Dlink dir-820l firmware improper access control vulnerability

Dlink · Dir 820l Firmware

The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.

8.8 CVSS 3.1 High EPSS 0.54% · top 56.8% CWE-284 · Improper access control
8.8CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-52079 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-25280D-Link DIR-820L ping.ccp OS Command InjectionThe D-Link DIR-820L router firmware (DIR820LA1_FW105B03) fails to sanitize the ping_addr parameter passed to ping.ccp, allowing OS command injection.…KEVEPSS 98%analysed9.8CVE-2022-26258D-Link DIR-820L router OS command injection via HTTP POSTD-Link DIR-820L firmware 1.05B03 contains an OS command injection flaw reachable through an HTTP POST request to the set ccp handler, allowing remote…KEVEPSS 92%analysed9.8CVE-2021-45382D-Link DIR series routers command injection in DDNS functionAn OS command injection flaw exists in the DDNS function of the ncc2 binary on multiple D-Link DIR router models (DIR-810L, DIR-820L/LW, DIR-826L, DI…KEVEPSS 98%analysed9.8CVE-2015-1187D-Link and TRENDnet ping tool command injection allows remote code executionThe ping tool in multiple D-Link and TRENDnet router and access point firmware fails to properly authenticate or sanitize the ping_addr parameter pas…KEVEPSS 83%analysed9.8CVE-2024-48150Dlink dir-820l firmware classic buffer overflow vulnerabilityD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.EPSS 0.71%9.8CVE-2023-44808Dlink dir-820l firmware out-of-bounds write vulnerabilityD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.EPSS 0.85%9.8CVE-2023-44809Dlink dir-820l firmware improper privilege management vulnerabilityD-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.EPSS 0.85%9.8CVE-2023-44807Dlink dir-820l firmware out-of-bounds write vulnerabilityD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2025-52079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.