A published proof-of-concept exploit targets a remotely reachable stack-based buffer overflow in the D-Link DIR-825M 1.1.8 LTE Module Firmware Upgrade endpoint, rated CVSS 3.1 9.9 (CRITICAL).
What Is It
A stack-based buffer overflow (CWE-121, CWE-119) in the function sub_41802C of /boafrm/formLtefotaUpgradeFibocom, part of the LTE Module Firmware Upgrade component on the D-Link DIR-825M router. Manipulating the fota_url argument triggers the overflow. The attack can be carried out remotely, and per the VulDB advisory, the exploit has been published and may be used.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and only low privileges required. The scope is marked Changed, with High confidentiality, integrity, and availability impact, producing a 9.9 base score. The CVSS 4.0 assessment lands lower at 8.6 (HIGH) and rates exploit maturity as PROOF_OF_CONCEPT. That 8.6 is only arithmetically consistent with no subsequent-system impact (SC:N/SI:N/SA:N), that is, impact confined to the vulnerable component; which sits in direct tension with the Changed scope asserted in the 3.1 vector. The two scores encode incompatible views of blast radius, and neither is independently corroborated below.
A stack overflow in a firmware-upgrade handler on a consumer LTE router is the kind of flaw that can plausibly lead to code execution and control over the device, though none of the available sources demonstrate a working end-to-end exploit chain or confirm that memory-corruption mitigations on this firmware have been defeated. What can be said with more confidence is that the published proof-of-concept reduces the reconnaissance and development effort an attacker would otherwise need to invest.
What's Vulnerable
- Vendor: D-Link
- Product: DIR-825M
- Version: 1.1.8 (affected)
- Component: LTE Module Firmware Upgrade
- Endpoint:
/boafrm/formLtefotaUpgradeFibocom - Parameter:
fota_url - CPE:
cpe:2.3:h:d-link:dir-825m:*:*:*:*:*:*:*:*
Patch Status
No CISA KEV entry accompanies this CVE, so there is no confirmation of active in-the-wild exploitation and no KEV-mandated remediation deadline at this time. The supplied source material, all of it VulDB-derived, plus the researcher's write-up, lists no patch, fixed version, or vendor advisory, and cites only the D-Link corporate site as a vendor reference. No mitigation guidance is present in that material, and no NVD analysis was available at the time of writing to corroborate the scoring or affected-version data above.
Sources
- VulDB, CVE-2026-82593: https://vuldb.com/cve/CVE-2026-82593
- VulDB entry 397088: https://vuldb.com/vuln/397088
- VulDB CTI data: https://vuldb.com/vuln/397088/cti
- VulDB submission 892516: https://vuldb.com/submit/892516
- Researcher report (Robots10/IoT_vlu): https://github.com/Robots10/IoT_vlu/blob/main/reports/Dlink/formLtefotaUpgradeFibocom/formLtefotaUpgradeFibocom.md
- D-Link: https://www.dlink.com/