ZeroHour

CVE-2026-82592

niche

Stack-Based Buffer Overflow in D-Link DIR-825M Disk Formatting Endpoint

CVSS 4.0
8.6 high
EPSS
<1%p53
Published
()
Modified
AI analysis

D-Link DIR-825M firmware 1.1.8 contains a stack-based buffer overflow in the Disk Formatting Handler Endpoint at /boafrm/formDiskFormat (function sub_46725C, CWE-119/CWE-121). An attacker can trigger the flaw remotely by sending a request to that endpoint with an overly long 'partition' argument, overwriting stack memory. Successful exploitation could crash the affected service and potentially allow arbitrary code execution on the router; the CVSS 4.0 score of 8.6 (high) reflects high impact on confidentiality, integrity and availability, with the attack requiring network access and low privileges and no user interaction. Only owners of D-Link DIR-825M routers, particularly those running firmware 1.1.8 with the web management interface reachable, are affected. The advisory states the exploit is now public and may be used, though no formal PoC is catalogued, the flaw is not yet in CISA's KEV, and EPSS currently estimates a 0.8% probability of exploitation in the next 30 days.

What to do: DIR-825M owners should verify their firmware version and update to the latest D-Link release when a patched build is published, as the advisory does not specify a fixed version. Until then, restrict the router's web management interface to trusted LAN clients and disable WAN-side remote management to limit exposure of the formDiskFormat endpoint. Defenders should also watch for vendor advisories and update this dashboard entry once a fixed firmware version or KEV listing is confirmed.

Affected
D-Link DIR-825M1.1.8 (version analyzed; no other version ranges specified in the data)
Estimated exposure
nicheunknown, plausibly tens of thousands of deployed units with likely fewer internet-exposed — No public install-base or internet-exposure scan data exists for this specific D-Link router model, so the estimate is a heuristic based on typical deployment volumes for a single niche consumer router variant rather than D-Link's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.