VYPR
Vypr IntelligenceAI-generatedAug 31, 2026· 3 CVEs

D-Link DIR-825M: Three Critical Remote Exploitable Vulnerabilities Disclosed Together

D-Link DIR-825M routers running firmware 1.1.8 are affected by three critical vulnerabilities, including two buffer overflows and a command injection flaw, all remotely exploitable.

Key findings

  • Three critical vulnerabilities disclosed for D-Link DIR-825M (firmware 1.1.8) on August 31, 2026.
  • Two critical flaws (CVSS 9.9) involve stack-based buffer overflows in firmware upgrade and disk formatting functions.
  • One high-severity flaw (CVSS 7.4) is a command injection vulnerability in the system command execution component.
  • All vulnerabilities are remotely exploitable and affect firmware version 1.1.8.
  • D-Link has released firmware version 1.1.8 to address these security issues.

On August 31, 2026, a batch of three critical vulnerabilities was disclosed for D-Link's DIR-825M router, specifically impacting firmware version 1.1.8. These flaws, reported by security researchers and coordinated through disclosure channels, collectively pose a significant risk to users due to their remote exploitability and high severity. Two of the vulnerabilities, CVE-2026-82593 and CVE-2026-82592, are rated Critical with a CVSSv3 score of 9.9, while CVE-2026-82595 is rated High with a CVSSv3 score of 7.4.

The vulnerabilities stem from insecure handling of user-supplied input within different system components. CVE-2026-82593 and CVE-2026-82592 both involve stack-based buffer overflows. CVE-2026-82593 affects the LTE Module Firmware Upgrade component, triggered by manipulating the fota_url argument in the /boafrm/formLtefotaUpgradeFibocom endpoint. CVE-2026-82592 impacts the Disk Formatting Handler Endpoint, where manipulating the partition argument in /boafrm/formDiskFormat leads to the overflow.

CVE-2026-82595, on the other hand, is a command injection vulnerability. It resides within the System Command Execution component, specifically in the /boafrm/formSysCmd endpoint. Attackers can exploit this by manipulating the sysCmd argument to inject arbitrary commands, gaining control over the affected device. All three vulnerabilities are exploitable remotely, meaning an attacker does not need physical access to the device to launch an attack.

The disclosure of these vulnerabilities highlights a critical need for users of the D-Link DIR-825M router, running firmware version 1.1.8, to take immediate action. While the provided information does not specify whether these vulnerabilities are being actively exploited in the wild or name any specific threat actors, their critical nature and remote exploitability warrant prompt attention. D-Link has released firmware version 1.1.8 to address these issues. Users are strongly advised to update their devices to the latest firmware as soon as possible to mitigate the risk of compromise.

This batch of vulnerabilities underscores the importance of regular security audits and timely patching for network infrastructure devices. Users should remain vigilant and ensure their D-Link DIR-825M routers are running the most up-to-date firmware to protect against potential attacks. Further advisories or updates from D-Link should be monitored for any additional information or recommended actions.

AI-written article. Grounded in 3 CVE records listed below.
D-Link DIR-825M: Three Critical Remote Exploitable Vulnerabilities Disclosed Together · VYPR