<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>DIR-825M (1.1.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dir-825m-1.1.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 01:12:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dir-825m-1.1.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Stack-Based Buffer Overflow in D-Link DIR-825M</title><link>https://feed.craftedsignal.io/briefs/2026-08-dlink-buffer-overflow/</link><pubDate>Mon, 31 Aug 2026 01:12:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-dlink-buffer-overflow/</guid><description>A critical stack-based buffer overflow vulnerability in D-Link DIR-825M firmware allows unauthenticated remote attackers to achieve code execution via the /boafrm/formDiskFormat endpoint.</description><content:encoded><![CDATA[<p>D-Link DIR-825M firmware version 1.1.8 contains a critical stack-based buffer overflow vulnerability identified as CVE-2026-82592. The vulnerability is located within the sub_46725C function of the Disk Formatting Handler component, specifically triggered through the /boafrm/formDiskFormat endpoint. By sending a maliciously crafted HTTP request containing an overly long 'partition' argument, an unauthenticated remote attacker can corrupt the stack, potentially leading to arbitrary code execution on the affected router. The exploit is currently public, significantly increasing the risk of exploitation by threat actors targeting small office/home office (SOHO) network infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to gain full control over the affected D-Link DIR-825M router. This can lead to complete device compromise, unauthorized network access, interception of traffic, and persistence within the victim's network. Given that these devices are typically internet-facing, the risk of widespread automated exploitation is high.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately restrict access to the web management interface of the D-Link DIR-825M to trusted internal IP addresses only.</li>
<li>Disable remote management features on all exposed D-Link devices to prevent unauthenticated access to the /boafrm/formDiskFormat endpoint.</li>
<li>Monitor network traffic for HTTP POST requests directed at the /boafrm/formDiskFormat path, particularly those containing suspicious strings or excessive length in the 'partition' parameter.</li>
<li>Check for firmware updates from the vendor; if no patch is available, replace the device or isolate it from the public internet.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>buffer-overflow</category><category>network-security</category></item></channel></rss>