ZeroHour

CVE-2026-82680

niche

Out-of-Bounds Write in D-Link DSM-G600 Multipart Handler (load_file.cgi)

CVSS 4.0
7.4 high
EPSS
<1%p36
Published
()
Modified
AI analysis

D-Link DSM-G600 firmware 1.01 contains an out-of-bounds write (CWE-787/CWE-119) in the Multipart Handler component, reachable via the /load_file.cgi file on the device's web interface. A remote attacker can trigger the flaw by sending manipulated data to this endpoint; per the CVSS 4.0 vector, the attack works over the network with no user interaction and requires only low-privileged access. A successful attack corrupts memory with high impact on the device's confidentiality, integrity, and availability, meaning an attacker could gain substantial control over or disrupt the device. Only operators of D-Link DSM-G600 storage routers running version 1.01, especially units whose web management interface is reachable from untrusted networks, are affected. A public exploit is available per the advisory (the CVSS vector also marks it as proof-of-concept), the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Inventory any D-Link DSM-G600 devices in use and check their firmware version, then apply the latest firmware available from D-Link for this model if an update has been published. Until patched, restrict remote/internet access to the device's web management interface (the load_file.cgi endpoint) with firewall rules, since the CVSS vector indicates low-privileged access is required for the attack. Given the device's age, retiring or replacing it is the most practical long-term mitigation.

Affected
D-Link DSM-G6001.01 (other versions not specified in available data)
Estimated exposure
nichelikely low thousands of remaining units worldwide (estimate; legacy consumer/SOHO network storage router) — The DSM-G600 is a legacy consumer/SOHO network storage device, so the surviving installed base and especially internet-exposed units are presumed small, though no public install-base or scan counts are available in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Weakness
CWE-119, CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.