CVE-2025-2621

Published Mar 22, 2025

Last updated 9 days ago

Overview

Description
A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Source
cna@vuldb.com
NVD status
Analyzed
CNA Tags
unsupported-when-assigned

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

CVSS 2.0

Type
Secondary
Base score
10
Impact score
10
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

cna@vuldb.com
CWE-119
nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-2621 ⚠️🔴 CRITICAL (9.3) 🏢 D-Link - DAP-1620 🏗️ 1.03 🔗 https://t.co/H5KRAzLQIv 🔗 https://t.co/Ob0O7cPvg6 🔗 https://t.co/xu2zZYBMiJ 🔗 https://t.co/TZJxYq7Pwx 🔗 https://t.co/sYyss3yo3N #CyberCron #VulnAlert #InfoSec https://t.co/IohPK41uyu

    @cybercronai

    24 Mar 2025

    180 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  2. 🚨 CVE-2025-2621 ⚠️🔴 CRITICAL (9.3) 🏢 D-Link - DAP-1620 🏗️ 1.03 🔗 https://t.co/H5KRAzMoy3 🔗 https://t.co/Ob0O7cQ35E 🔗 https://t.co/xu2zZYCk8h 🔗 https://t.co/TZJxYq8nm5 🔗 https://t.co/sYyss3yVTl #CyberCron #VulnAlert #InfoSec https://t.co/TtTDSbGkxb

    @cybercronai

    22 Mar 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. �� CVE-2025-2621 - D-Link DAP-1620 - HIGH 🚨 🗓️ Date published 2025-03-22 17:15:34 UTC #D-LinkDAP-1620 #CyberSecurity #InfoSec #Vulnerability #TechNews https://t.co/K1mbc6Hne5

    @vulns_space

    22 Mar 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-2621 D-Link DAP-1620 Remote Stack Overflow Vulnerability in check_dws_cookie Function https://t.co/92FqpUly3z

    @VulmonFeeds

    22 Mar 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-2621: CRITICAL] Critical vulnerability in D-Link DAP-1620 1.03 allows remote attackers to trigger a stack-based buffer overflow. Product no longer supported.#cybersecurity,#vulnerability https://t.co/PooQnXSQ56 https://t.co/TUlUJulksx

    @CveFindCom

    22 Mar 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-2621 A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of… https://t.co/f5AbFhCqhe

    @CVEnew

    22 Mar 2025

    605 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations