CVE-2026-82680
nicheOut-of-Bounds Write in D-Link DSM-G600 Multipart Handler (load_file.cgi)
D-Link DSM-G600 firmware 1.01 contains an out-of-bounds write (CWE-787/CWE-119) in the Multipart Handler component, reachable via the /load_file.cgi file on the device's web interface. A remote attacker can trigger the flaw by sending manipulated data to this endpoint; per the CVSS 4.0 vector, the attack works over the network with no user interaction and requires only low-privileged access. A successful attack corrupts memory with high impact on the device's confidentiality, integrity, and availability, meaning an attacker could gain substantial control over or disrupt the device. Only operators of D-Link DSM-G600 storage routers running version 1.01, especially units whose web management interface is reachable from untrusted networks, are affected. A public exploit is available per the advisory (the CVSS vector also marks it as proof-of-concept), the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Inventory any D-Link DSM-G600 devices in use and check their firmware version, then apply the latest firmware available from D-Link for this model if an update has been published. Until patched, restrict remote/internet access to the device's web management interface (the load_file.cgi endpoint) with firewall rules, since the CVSS vector indicates low-privileged access is required for the attack. Given the device's age, retiring or replacing it is the most practical long-term mitigation.
| D-Link DSM-G600 | 1.01 (other versions not specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
- Weakness
- CWE-119, CWE-787
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.