Skip to content
Threat Feed
high advisory

Remote Out-of-Bounds Write Vulnerability in D-Link DSM-G600

A critical out-of-bounds write vulnerability in the D-Link DSM-G600 multipart handler allows remote attackers to compromise the device via the /load_file.cgi endpoint, with public exploit code currently available.

CVE search metadata

CVE search record: CVE-2026-82680. Severity: high. CVSS: 8.8. KEV: no. Product: DSM-G600 (1.01). Brief: Remote Out-of-Bounds Write Vulnerability in D-Link DSM-G600. Brief link: https://feed.craftedsignal.io/briefs/2026-08-dlink-dsm-g600-oob-write/

D-Link DSM-G600 version 1.01 contains a critical vulnerability within the multipart handler component, specifically located in the /load_file.cgi script. This flaw allows a remote, unauthenticated attacker to trigger an out-of-bounds write condition. Because the device handles multipart requests, improper bounds checking during the processing of these requests enables the corruption of memory, which can lead to arbitrary code execution or permanent system instability. Public exploit code for this vulnerability is currently available, significantly lowering the barrier for exploitation by malicious actors. Given the nature of the device as a storage/network component, successful exploitation could provide an attacker with a foothold for lateral movement within the internal network or the exfiltration of stored data.

Impact

Successful exploitation of CVE-2026-82680 allows for remote code execution on the affected D-Link DSM-G600 devices. This impact represents a high risk to organizational security, as compromised network storage devices can be leveraged for persistence, internal reconnaissance, or as a pivot point for further network attacks.

Recommendation

Prioritize the decommissioning or isolation of legacy D-Link DSM-G600 devices, as version 1.01 is significantly outdated and lacks modern security hardening. For environments where the device cannot be decommissioned, ensure that the /load_file.cgi endpoint is not accessible from untrusted or public-facing network segments. Implement network-level access control lists (ACLs) to restrict traffic to the management interface of the device to known, authorized administrative IP addresses.


Immediate actions

Restrict network access to /load_file.cgi on D-Link DSM-G600 devices using firewall or ACL rules.

IT Operations 24h

Mitigations

Decommission D-Link DSM-G600 devices or move to isolated network segments.

immediate IT Operations

CVE-2026-82680