CVE-2025-10666
HIGHEPSS 86th pctlDescription
A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
Elevated risk: more likely to be exploited than 86% of all known CVEs.
References
- https://github.com/panda666-888/vuls/blob/main/d-link/dir-825/apply.cgi.md
- https://github.com/panda666-888/vuls/blob/main/d-link/dir-825/apply.cgi.md#poc
- https://vuldb.com/?ctiid.324787
- https://vuldb.com/?id.324787
- https://vuldb.com/?submit.652047
- https://www.dlink.com/
- https://www.exploit-db.com/exploits/52469
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-02-03.