A public proof-of-concept exists for a remotely exploitable stack-based buffer overflow in the D-Link DIR-825M router's disk formatting endpoint, rated CVSS 3.1 9.9 (Critical).
What Is It
CVE-2026-82592 is a stack-based buffer overflow (CWE-121 / CWE-119) in D-Link DIR-825M firmware version 1.1.8. The flaw sits in the function sub_46725C handling /boafrm/formDiskFormat, the Disk Formatting Handler Endpoint. An attacker who manipulates the partition argument overflows a stack buffer. The attack is executed remotely and, per the CVE record, the exploit is now public and may be used.
Why It Matters
The CVSS 3.1 base score is 9.9 (Critical), vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is Changed, with High impact to confidentiality, integrity, and availability. The CVSS 4.0 assessment from the CNA scores it 8.6 (High) with an exploit maturity of Proof-of-Concept, and the CVSS 2.0 score is 9.0.
Stack-based overflows in an embedded HTTP handler like this one put the device itself at risk, and the combination of remote reachability, low complexity, and a published exploit narrows the window for defenders considerably.
What's Vulnerable
- Vendor: D-Link
- Product: DIR-825M (hardware)
- Affected version: 1.1.8
- Component: Disk Formatting Handler Endpoint (
/boafrm/formDiskFormat, functionsub_46725C) - CPE:
cpe:2.3:h:d-link:dir-825m:*:*:*:*:*:*:*:*
No other products or versions are listed in the source data.
Patch Status
The supplied source material contains no patch, fixed version, or vendor advisory for this issue. CVE-2026-82592 does not currently appear in the CISA KEV catalog, so there is no KEV-mandated remediation deadline; KEV listing lags real-world activity and its absence is not evidence that exploitation is not occurring, particularly with a public proof-of-concept documented. NVD lists the record as Received (published 2026-08-30), meaning analysis is not yet complete. Consult the D-Link vendor site for firmware updates.
Sources
- NVD, CVE-2026-82592: https://nvd.nist.gov/vuln/detail/CVE-2026-82592
- VulDB, CVE-2026-82592: https://vuldb.com/cve/CVE-2026-82592
- VulDB, Vulnerability 397087: https://vuldb.com/vuln/397087
- VulDB, Threat Intelligence (397087): https://vuldb.com/vuln/397087/cti
- VulDB, Submission 892514: https://vuldb.com/submit/892514
- Researcher report (Robots10/IoT_vlu): https://github.com/Robots10/IoT_vlu/blob/main/reports/Dlink/formDiskFormat/formDiskFormat.md
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- D-Link: https://www.dlink.com/