← Vulnerability feed

Vulnerability record · CVE-2026-7069 · published 27 April 2026

CVE-2026-7069: Dlink dir-825 firmware memory buffer overflow vulnerability

Dlink · Dir 825 Firmware

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

7.3 CVSS 4.0 High EPSS 0.75% · top 47.1% CWE-119 · Memory buffer overflowCWE-120 · Classic buffer overflow
7.3CVSS 4.0 base score, v2 7.7
0.75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7069 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2022-47035Dlink dir-825 firmware classic buffer overflow vulnerabilityBuffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method…EPSS 1.2%9.8CVE-2021-46442D-Link DIR-825 webupg authentication bypass via autoupgrade.aspThe webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated …EPSS 56%analysed8.9CVE-2025-7206Dlink dir-825 firmware memory buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file swit…EPSS 18%8.8CVE-2021-46441Dlink dir-825 firmware os command injection vulnerabilityIn the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s…EPSS 33%8.8CVE-2020-10213Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …EPSS 5.0%8.8CVE-2020-10214Dlink dir-825 firmware out-of-bounds write vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated …EPSS 18%8.8CVE-2020-10215Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2026-7069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.