← Back to overview

A stack-based buffer overflow vulnerability has been identified in D-Link DIR-825M firmware version 1.1.8. The flaw exists in the function sub_41802C within the file /boafrm/formLtefotaUpgradeFibocom, which is part of the LTE Module Firmware Upgrade component. The vulnerability is triggered by manipulating the 'fota_url' argument, leading to a stack-based buffer overflow condition. The attack can be executed remotely without physical access to the device. A public exploit has already been published, increasing the risk of active exploitation. This affects IoT and network infrastructure devices, specifically D-Link routers with LTE capabilities. The availability of a public exploit makes this a high-priority vulnerability for patching and mitigation.

Affected products

  • D-Link DIR-825M 1.1.8

Related CVE's

  • CVE-2026-82593

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities