ZeroHour

CVE-2026-82593

moderate

Remote Stack Buffer Overflow in D-Link DIR-825M LTE Firmware Upgrade (CVE-2026-82593)

CVSS 4.0
8.6 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-82593 is a stack-based buffer overflow (CWE-119/CWE-121) in the LTE Module Firmware Upgrade component of the boa web server on D-Link DIR-825M routers, specifically in function sub_41802C of the handler /boafrm/formLtefotaUpgradeFibocom. A remote attacker triggers it by submitting an overlong or crafted fota_url parameter to that endpoint, overflowing a fixed on-stack buffer; the CVSS 4.0 vector (AV:N/PR:L/UI:N) indicates network-based exploitation with low-privileged access and no user interaction. Successful overflow could allow remote code execution on the router, or at minimum a crash of the HTTP service, consistent with the high confidentiality, integrity and availability impacts in the 8.6 (High) CVSS 4.0 score. Only DIR-825M devices on the affected firmware are impacted; practically, units whose management web interface is reachable over the network (exposed to the WAN, port-forwarded, or accessed by an attacker already on the LAN). The exploit has been published and may be used (CVSS 4.0 exploit maturity E:P), although no standalone public proof-of-concept is catalogued; EPSS currently estimates a 0.5% probability of exploitation within 30 days and the flaw is not yet in CISA's KEV catalog.

What to do: DIR-825M owners should verify their firmware version and, if on 1.1.8, apply D-Link's patched firmware as soon as it is released (no fixed version number is stated in the available data), and confirm with D-Link whether other firmware versions are affected. In the meantime, avoid exposing the router's web management interface to the WAN and restrict admin access to trusted LAN hosts. Given the published exploit, monitor for abnormal or oversized fota_url requests to /boafrm/formLtefotaUpgradeFibocom and consider blocking or rate-limiting them at the network edge.

Affected
D-Link DIR-825M (LTE Module Firmware Upgrade, boafrm/formLtefotaUpgradeFibocom)1.1.8 (confirmed; broader affected version range not specified in available data)
Estimated exposure
moderate≈ tens of thousands of devices (estimate; single regional consumer LTE router model) — No public install-base counts or internet-exposure scans are available for this LTE variant of the DIR-825 line, so the magnitude is inferred from typical deployment patterns of single-model consumer LTE routers, with only units whose web…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.