CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-15191: dwr-m920 firmware through 1.1.50 (inclusive); +1 more affected products

CVE-2025-15191. CVSS 3.1 base score 8.8 (HIGH, NVD). EPSS 0.0413 (percentile 0.90537), scored 2026-10-06.

Affected technology

dwr-m920 firmware · through 1.1.50 (inclusive)
dlink

DWR-M920 · 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9, 1.1.10, 1.1.11, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19, 1.1.20, 1.1.21, 1.1.22, 1.1.23, 1.1.24, 1.1.25, 1.1.26, 1.1.27, 1.1.28, 1.1.29, 1.1.30, 1.1.31, 1.1.32, 1.1.33, 1.1.34, 1.1.35, 1.1.36, 1.1.37, 1.1.38, 1.1.39, 1.1.40, 1.1.41, 1.1.42, 1.1.43, 1.1.44, 1.1.45, 1.1.46, 1.1.47, 1.1.48, 1.1.49, 1.1.50
D-Link

Description’s affected range: up to 1.1.50

Component: Not specified by the source
Function: sub_4155B4
File: /boafrm/formLtefotaUpgradeFibocom

Attack conditions (VulDB, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

VulDB’s CVSS 4.0 assessment (base score 2.1/10) rates confidentiality, integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-74, CWE-77
CCR priority
36.2 /100 (P4)
CVSS 3.1
8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.0413 · percentile 0.90537 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-15191.html