A vulnerability has been identified in D-Link DSM-G600 version 1.01 affecting the /load_file.cgi file within the Multipart Handler component. The flaw allows an attacker to trigger an out-of-bounds write through manipulation of an unknown function. The attack can be launched remotely without requiring physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-82680 and has been documented in VulnDB and GitHub. D-Link network storage devices are the affected product class. The public availability of the exploit significantly elevates the threat level for unpatched devices. Organizations using D-Link DSM-G600 should monitor for patches and apply mitigations immediately.