Description
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
Published: 2025-10-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:dlink:dir-820l_firmware:1.06:b02:*:*:*:*:*:* cpe:2.3:o:dlink:dir-820l_firmware:1.06b02:*:*:*:*:*:*:*

Tue, 28 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dlink dir-820l Firmware
CPEs cpe:2.3:h:dlink:dir-820l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-820l_firmware:1.06:b02:*:*:*:*:*:*
Vendors & Products Dlink dir-820l Firmware

Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-820l
Vendors & Products Dlink
Dlink dir-820l

Wed, 22 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
Description The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
References

Subscriptions

Dlink Dir-820l Dir-820l Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-22T15:13:25.667Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-52079

cve-icon Vulnrichment

Updated: 2025-10-21T20:28:49.940Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-21T20:20:40.347

Modified: 2025-11-03T19:00:58.507

Link: CVE-2025-52079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-23T10:12:48Z

Weaknesses