VYPR
patchPublished Aug 31, 2026· Updated Sep 1, 2026· 1 source

D-Link: Nine Critical Command Injection and Buffer Overflow Vulnerabilities Disclosed Together

Key findings • Nine vulnerabilities disclosed for D-Link devices, including DNS NAS and DIR routers, within a 14-hour window. • Multiple critical command injection flaws found in D-Link DNS s…

Key findings

  • Nine vulnerabilities disclosed for D-Link devices, including DNS NAS and DIR routers, within a 14-hour window.
  • Multiple critical command injection flaws found in D-Link DNS series CGI handlers, allowing remote code execution.
  • Critical stack-based buffer overflows affect D-Link DIR-825M firmware upgrade and disk formatting functions.
  • Exploits are publicly available for several of the disclosed vulnerabilities, increasing immediate risk.
  • D-Link DIR-825M firmware 1.1.8 patched, users advised to update all affected D-Link devices promptly.

On August 31, 2026, a batch of nine vulnerabilities was disclosed for D-Link devices, spanning multiple product lines including DNS series NAS devices and DIR series routers. The vulnerabilities, disclosed within a 14-hour window, primarily involve remote command injection and buffer overflow flaws, with several carrying critical CVSS scores up to 9.9. These issues affect various models such as the DNS-340L, DNS-345, DNS-320L, DNS-327L, DSM-G600, and DIR-825M.

A significant portion of the disclosed vulnerabilities, specifically CVE-2026-82692, CVE-2026-82691, CVE-2026-82690, CVE-2026-82689, and CVE-2026-82688, are command injection flaws affecting the CGI handlers of D-Link's DNS series Network Attached Storage (NAS) devices. These vulnerabilities, present in versions up to 20260717, allow remote attackers to execute arbitrary commands by manipulating arguments in various CGI scripts, including those for iSCSI management, USB device handling, virtual volume management, and ISO image mounting. CVE-2026-82680, a high-severity weakness affecting the DSM-G600, also involves a command manipulation leading to an out-of-bounds write.

The D-Link DIR-825M router is impacted by three critical vulnerabilities, as detailed in related reporting. CVE-2026-82593 and CVE-2026-82592, both with a CVSS score of 9.9, are stack-based buffer overflows. The former affects the LTE Module Firmware Upgrade component, while the latter targets the Disk Formatting Handler Endpoint. Both allow for remote exploitation. Additionally, CVE-2026-82595, a high-severity command injection vulnerability, affects the System Command Execution component of the DIR-825M. All three of these DIR-825M vulnerabilities are present in firmware version 1.1.8 and are remotely exploitable.

The disclosures highlight a pattern of critical command injection and buffer overflow vulnerabilities across D-Link's product portfolio. The remote nature of these exploits and the critical severity ratings underscore the significant risk to users if these devices are not updated. The fact that exploits have been published for several of these CVEs increases the urgency for users to apply patches.

D-Link has addressed some of these vulnerabilities. For the DIR-825M, firmware version 1.1.8 has been released to patch CVE-2026-82592, CVE-2026-82593, and CVE-2026-82595. For the DNS series devices, the affected versions are noted as being up to 20260717, implying that versions released after this date may contain fixes, though specific patch version numbers were not universally provided for all affected DNS models in the batch. Users are strongly advised to check for and apply the latest firmware updates for their specific D-Link devices.

This batch of vulnerabilities serves as a critical reminder for D-Link customers to maintain up-to-date firmware on their network-attached storage devices and routers. The widespread nature of command injection flaws across multiple CGI interfaces in the DNS series, coupled with severe buffer overflows in the DIR-825M, presents a substantial attack surface. Proactive patching and regular security audits are essential to mitigate the risks associated with these and future disclosures. The coordinated disclosure of these nine CVEs emphasizes the importance of timely patching to protect against potential exploitation.

Synthesized by Vypr AI