SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-29332

D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal.

MEDIUM 6.5EPSS 1.43%

Does this matter?

Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.

Description

D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.43% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
dlink/dir-825 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.