{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3hdlinkdir-825m1.1.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:dlink:dir-825m:1.1.8:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-82592"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DIR-825M (1.1.8)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","buffer-overflow","network-security"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DIR-825M firmware version 1.1.8 contains a critical stack-based buffer overflow vulnerability identified as CVE-2026-82592. The vulnerability is located within the sub_46725C function of the Disk Formatting Handler component, specifically triggered through the /boafrm/formDiskFormat endpoint. By sending a maliciously crafted HTTP request containing an overly long 'partition' argument, an unauthenticated remote attacker can corrupt the stack, potentially leading to arbitrary code execution on the affected router. The exploit is currently public, significantly increasing the risk of exploitation by threat actors targeting small office/home office (SOHO) network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to gain full control over the affected D-Link DIR-825M router. This can lead to complete device compromise, unauthorized network access, interception of traffic, and persistence within the victim's network. Given that these devices are typically internet-facing, the risk of widespread automated exploitation is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the web management interface of the D-Link DIR-825M to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eDisable remote management features on all exposed D-Link devices to prevent unauthenticated access to the /boafrm/formDiskFormat endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for HTTP POST requests directed at the /boafrm/formDiskFormat path, particularly those containing suspicious strings or excessive length in the 'partition' parameter.\u003c/li\u003e\n\u003cli\u003eCheck for firmware updates from the vendor; if no patch is available, replace the device or isolate it from the public internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T01:13:06Z","date_published":"2026-08-31T01:12:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dlink-buffer-overflow/","summary":"A critical stack-based buffer overflow vulnerability in D-Link DIR-825M firmware allows unauthenticated remote attackers to achieve code execution via the /boafrm/formDiskFormat endpoint.","title":"Remote Stack-Based Buffer Overflow in D-Link DIR-825M","url":"https://feed.craftedsignal.io/briefs/2026-08-dlink-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:dlink:dir-825m:1.1.8:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}