Skip to content
Threat Feed
critical advisory

Remote Stack-Based Buffer Overflow in D-Link DIR-825M

A critical stack-based buffer overflow vulnerability in D-Link DIR-825M firmware allows unauthenticated remote attackers to achieve code execution via the /boafrm/formDiskFormat endpoint.

CVE search metadata

CVE search record: CVE-2026-82592. Severity: critical. CVSS: 9.9. KEV: no. Product: DIR-825M (1.1.8). Brief: Remote Stack-Based Buffer Overflow in D-Link DIR-825M. Brief link: https://feed.craftedsignal.io/briefs/2026-08-dlink-buffer-overflow/

What's new

  • 1. added coverage for DIR-825M (1.1.8) Aug 31, 01:13 via nvd

D-Link DIR-825M firmware version 1.1.8 contains a critical stack-based buffer overflow vulnerability identified as CVE-2026-82592. The vulnerability is located within the sub_46725C function of the Disk Formatting Handler component, specifically triggered through the /boafrm/formDiskFormat endpoint. By sending a maliciously crafted HTTP request containing an overly long 'partition' argument, an unauthenticated remote attacker can corrupt the stack, potentially leading to arbitrary code execution on the affected router. The exploit is currently public, significantly increasing the risk of exploitation by threat actors targeting small office/home office (SOHO) network infrastructure.

Impact

Successful exploitation of this vulnerability allows unauthenticated remote attackers to gain full control over the affected D-Link DIR-825M router. This can lead to complete device compromise, unauthorized network access, interception of traffic, and persistence within the victim's network. Given that these devices are typically internet-facing, the risk of widespread automated exploitation is high.

Recommendation

  • Immediately restrict access to the web management interface of the D-Link DIR-825M to trusted internal IP addresses only.
  • Disable remote management features on all exposed D-Link devices to prevent unauthenticated access to the /boafrm/formDiskFormat endpoint.
  • Monitor network traffic for HTTP POST requests directed at the /boafrm/formDiskFormat path, particularly those containing suspicious strings or excessive length in the 'partition' parameter.
  • Check for firmware updates from the vendor; if no patch is available, replace the device or isolate it from the public internet.

Immediate actions

Restrict external access to device management interfaces.

IT Operations 24h

Threat Hunt

Search web logs for suspicious strings in the partition parameter of the /boafrm/formDiskFormat endpoint.

T1190 high high confidence hunt now

Mitigations

Disable remote web management on vulnerable D-Link DIR-825M devices.

immediate IT Operations

CVE-2026-82592

Detection coverage 1

Detects CVE-2026-82592 Exploitation - Malicious POST to Disk Formatting Endpoint

critical

Detects exploitation attempts against CVE-2026-82592 by monitoring for POST requests to the /boafrm/formDiskFormat endpoint with potentially malicious partition parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →