An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
https://www.dlink.ru/ru/download2/5/19/2354/441/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29557