
🚨 HIGH: CVE-2025-15193 (CVSS 8.8) - Buffer overflow in D-Link DWR-M920 routers (≤v1.1.50). Remotely exploitable, public exploit available. Patch immediately or disable remote access. #CVE #PatchNow #ThreatIntel https://t.co/OQP0miqNa3
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 2 products

🚨 HIGH: CVE-2025-15193 (CVSS 8.8) - Buffer overflow in D-Link DWR-M920 routers (≤v1.1.50). Remotely exploitable, public exploit available. Patch immediately or disable remote access. #CVE #PatchNow #ThreatIntel https://t.co/OQP0miqNa3
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| HW | dlink | dwr-m920 | - | - | - |
| OS | dlink | dwr-m920_firmware | - | - | - |