CVE-2025-13306
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
- Dlink dwr-m920 Firmware
- = 1.1.5
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 8.3% (94th percentile)
- Weakness
- CWE-74, CWE-77, CWE-78
- NVD status
- Analyzed
- Published
- 2025-11-17
CVE-2025-13306 at NVD
No indexed exploits for CVE-2025-13306 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-13306 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.