Cyber & AI intelligence
Wasteland.
Briefs indexed2329
Issues25
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82592 2026-08-30

CVE-2026-82592: Stack Overflow in D-Link DIR-825M Disk Format Handler

"A public proof-of-concept exists for a remotely exploitable stack-based buffer overflow in the D-Link DIR-825M router's disk formatting endpoint, rated CVSS 3.1 9.9 (Critical)."

A public proof-of-concept exists for a remotely exploitable stack-based buffer overflow in the D-Link DIR-825M router's disk formatting endpoint, rated CVSS 3.1 9.9 (Critical).

What Is It

CVE-2026-82592 is a stack-based buffer overflow (CWE-121 / CWE-119) in D-Link DIR-825M firmware version 1.1.8. The flaw sits in the function sub_46725C handling /boafrm/formDiskFormat, the Disk Formatting Handler Endpoint. An attacker who manipulates the partition argument overflows a stack buffer. The attack is executed remotely and, per the CVE record, the exploit is now public and may be used.

Why It Matters

The CVSS 3.1 base score is 9.9 (Critical), vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is Changed, with High impact to confidentiality, integrity, and availability. The CVSS 4.0 assessment from the CNA scores it 8.6 (High) with an exploit maturity of Proof-of-Concept, and the CVSS 2.0 score is 9.0.

Stack-based overflows in an embedded HTTP handler like this one put the device itself at risk, and the combination of remote reachability, low complexity, and a published exploit narrows the window for defenders considerably.

What's Vulnerable

No other products or versions are listed in the source data.

Patch Status

The supplied source material contains no patch, fixed version, or vendor advisory for this issue. CVE-2026-82592 does not currently appear in the CISA KEV catalog, so there is no KEV-mandated remediation deadline; KEV listing lags real-world activity and its absence is not evidence that exploitation is not occurring, particularly with a public proof-of-concept documented. NVD lists the record as Received (published 2026-08-30), meaning analysis is not yet complete. Consult the D-Link vendor site for firmware updates.

Sources