Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-82592: D-Link DIR-825M router allows remote code execution via disk format

CVE-2026-82592 · published 3 days ago
Summary

The router’s disk formatting feature can be tricked into overwriting memory, letting an attacker run their own code from anywhere on the internet. This could let a hacker take control of the device or disrupt your network. Install the latest firmware from D-Link as soon as possible and disable unused disk‑formatting functions until the update is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-825m 1.1.8
Original advisory text
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of...
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Severity
8.6 High
CVSS 2.0: 9.0 (NVD)
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 8.6 (NVD)
Exploitation
EPSS <1%
Type
CWE-119Buffer Overflow
CWE-121Stack-based Buffer Overflow
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82592 · MITRE
Monitor software like this
Free during beta