← Back to overview

A command injection vulnerability has been identified in D-Link DIR-825M firmware version 1.1.8. The vulnerability resides in the function sub_456CF4 within the file /boafrm/formSysCmd, part of the System Command Execution component. An attacker can manipulate the 'sysCmd' argument to inject arbitrary operating system commands. The attack can be initiated remotely without physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-82595 and has been submitted to VulDB. D-Link home/SMB routers are the affected product class. Users are advised to monitor for patches or apply mitigations. The public disclosure and exploit availability make this a high-priority issue for affected device owners.

Affected products

  • D-Link DIR-825M 1.1.8

Related CVE's

  • CVE-2026-82595

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities