Overview
On August 31, 2026, D-Link Systems, Inc. (US) became aware of three reported security vulnerabilities concerning the (Non-US) D-Link DIR-825M running firmware version 1.1.8.
The reported vulnerabilities affect separate functions within the device's web-management interface and include two stack-based buffer overflow vulnerabilities and one command-injection vulnerability:
1. A stack-based buffer overflow involving the Disk Formatting Handler.
2. A stack-based buffer overflow involving the LTE Module Firmware Upgrade handler.
3. A command-injection vulnerability involving the System Command Execution handler.
The vulnerabilities have been assigned CVE-2026-82592, CVE-2026-82593, and CVE-2026-82595. The published CVE records identify DIR-825M firmware version 1.1.8 as affected. (CVE)
D-Link takes network security and user privacy seriously. D-Link maintains product-management and security-response resources to investigate reported security issues and provide appropriate product updates.
Report Information
Reported Product: DIR-825M
Reported Firmware: 1.1.8
Number of Reported Issues: 3
CVE IDs: CVE-2026-82592, CVE-2026-82593, CVE-2026-82595
CVE Assigning CNA: VulDB
Security Researcher: hacker128
Resolution Status: Under Investigation / Open
Report 1 — Stack-Based Buffer Overflow in Disk Formatting Handler
The researcher reported a stack-based buffer overflow involving the DIR-825M Disk Formatting Handler. The issue is associated with processing of the partition argument by the sub_46725C function within /boafrm/formDiskFormat. (CVE)
CVE: CVE-2026-82592
Component: Disk Formatting Handler Endpoint
URI: /boafrm/formDiskFormat
Function: sub_46725C
Affected Field: partition
Vulnerability Type: Stack-Based Buffer Overflow
CWE: CWE-119, CWE-121
CVSS v3.1: 9.9 / Critical
Affected Firmware: 1.1.8
Status: Under Investigation
The CVSS v3.1 vector assigned by the CNA is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The published assessment therefore specifies that low privileges are required, and no user interaction is required. (CVE)
Report 2 — Stack-Based Buffer Overflow in LTE Module Firmware Upgrade Handler
The researcher reported a stack-based buffer overflow involving the LTE Module Firmware Upgrade handler. The issue is associated with processing of the fota_url argument by the sub_41802C function within /boafrm/formLtefotaUpgradeFibocom. (OpenCVE)
CVE: CVE-2026-82593
Component: LTE Module Firmware Upgrade
URI: /boafrm/formLtefotaUpgradeFibocom
Function: sub_41802C
Affected Field: fota_url
Vulnerability Type: Stack-Based Buffer Overflow
CWE: CWE-119, CWE-121
CVSS v3.1: 9.9 / Critical
Affected Firmware: 1.1.8
Status: Under Investigation
The published CVSS v3.1 assessment also specifies that low privileges are required, and no user interaction is required. (OpenCVE)
Report 3 — Command Injection in System Command Execution Handler
The researcher reported a command-injection vulnerability involving the DIR-825M System Command Execution handler. The issue is associated with processing of the sysCmd argument by the sub_456CF4 function within /boafrm/formSysCmd. (OpenCVE)
CVE: CVE-2026-82595
Component: System Command Execution
URI: /boafrm/formSysCmd
Function: sub_456CF4
Affected Field: sysCmd
Vulnerability Type: Command Injection
CWE: CWE-74, CWE-77
CVSS v3.1: 7.4 / High
Affected Firmware: 1.1.8
Status: Under Investigation
The CNA-assigned CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L, which specifies low privileges are required and no user interaction is required. (OpenCVE)
Affected Models
|
Model
|
Hardware Revision
|
Affected Software Version
|
Region
|
Fixed Release
|
Last Updated
|
|
DIR-825M
|
Ax*
|
1.1.8
|
Global / Non-US Product
|
Under Research
|
08/31/2026
|
*The currently published CVE records identify the DIR-825M and firmware 1.1.8, but do not independently specify the hardware revision. The existing D-Link DIR-825M security announcement identifies hardware revision Ax. D-Link engineering should confirm this hardware-revision scope before final publication. (D-Link Support)
Regarding the Security Update for Your D-Link Device
D-Link is reviewing the reported vulnerabilities and the affected firmware.
At the time of this announcement, D-Link has not yet confirmed a fixed firmware release for CVE-2026-82592, CVE-2026-82593, and CVE-2026-82595 for publication.
D-Link recommends that customers regularly check the applicable regional D-Link support resources for firmware updates applicable to their product model and hardware revision.
When an updated firmware release becomes available, users should install the firmware designated specifically for their DIR-825M hardware revision and verify that the firmware installation completed successfully by comparing the firmware version displayed in the device's web-based administration interface with the installed release.
D-Link Systems, Inc. identifies the DIR-825M as a Non-US product. Product availability, firmware releases, and support procedures may vary by country or regional D-Link organization. (D-Link Support)
Important Hardware-Revision Notice
D-Link products may be produced in multiple hardware revisions. Firmware is specific to the applicable model and hardware revision.
Before installing any firmware update:
1. Confirm that the product model is DIR-825M.
2. Confirm the hardware revision printed on the product label.
3. Download only firmware designated for that model and hardware revision.
4. Follow the firmware-installation instructions provided by the applicable regional D-Link support organization.
The hardware revision is on the product label near the serial number and may also appear in the device's web-based administration interface.
Acknowledgment
D-Link thanks hacker128 for reporting these vulnerabilities through the vulnerability disclosure process.
The CVE identifiers were assigned by VulDB:
· CVE-2026-82592 — DIR-825M Disk Formatting Handler stack-based buffer overflow. (CVE)
· CVE-2026-82593 — DIR-825M LTE Module Firmware Upgrade stack-based buffer overflow. (OpenCVE)
· CVE-2026-82595 — DIR-825M System Command Execution command injection. (OpenCVE)
Publication issue I would resolve before posting
The only material blocker is hardware/firmware remediation scope. The CVEs establish DIR-825M v1.1.8, but they do not establish a fixed release. Also, the CVEs do not explicitly say Ax, even though D-Link's existing DIR-825M SAP10477 does. I therefore would not broaden “1.1.8” to “1.xx or earlier” or state that an existing firmware fixes these three CVEs until engineering confirms it.