Buffer Overflow Vulnerability in D-Link DIR-825M Router
CVE-2026-7289
Key Information:
Badges
What is CVE-2026-7289?
A vulnerability exists in the D-Link DIR-825M router software version 1.1.12 that affects the handling of the submit-url argument in the function sub_414BA8 located in the /boafrm/formWanConfigSetup file. This flaw can lead to a buffer overflow, allowing attackers to execute arbitrary code remotely. The nature of this vulnerability poses a significant risk as the exploit has been made public, highlighting the need for immediate attention and mitigation strategies from users.
Affected Version(s)
DIR-825M 1.1.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved