CVE-2025-5215
Last modified
CVE-2025-5215 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. The manipulation of the argument Authorization leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dcs-5020l Firmware | 1.01_b2 |
References
- https://github.com/xiaobor123/vul-dlink-dcs5020lExploit, Third Party Advisory
- https://github.com/xiaobor123/vul-dlink-dcs5020l#pocExploit, Third Party Advisory
- https://vuldb.com/?ctiid.310311Permissions Required, VDB Entry
- https://vuldb.com/?id.310311Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.582935Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
- https://github.com/xiaobor123/vul-dlink-dcs5020lExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5215?
How severe is CVE-2025-5215?
How do I fix CVE-2025-5215?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52130File upload vulnerability in WebErpMesv2 1.17 in the app/Htt…5.4
- CVE-2025-52131The Mocca Calendar application before 2.15 for XWiki allows …6.4
- CVE-2025-52132The Mocca Calendar application before 2.15 for XWiki allows …6.4
- CVE-2025-52133The Mocca Calendar application before 2.15 for XWiki allows …6.4
- CVE-2025-52136In EMQX before 5.8.6, administrators can install arbitrary n…3
- CVE-2025-5214A vulnerability was found in Kashipara Responsive Online Lea…9.8
- CVE-2025-52159Hardcoded credentials in default configuration of PPress 0.0…8.8
- CVE-2025-5216A vulnerability classified as critical was found in PHPGuruk…9.8
- CVE-2025-52161Scholl Communications AG Weblication CMS Core v019.004.000.0…9.8
- CVE-2025-52162agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was…6.5
- CVE-2025-52163A Server-Side Request Forgery (SSRF) in the component Tunnel…6.5
- CVE-2025-52164Software GmbH Agorum core open v11.9.2 & v11.10.1 was discov…8.2
Are you affected by CVE-2025-5215?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
