SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82593

CRITICAL · CVSS 9.9 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in the LTE Module Firmware Upgrade function of D-Link DIR-825M devices, allowing remote attackers to manipulate the fota_url argument. This critical flaw, with a CVSS score of 9.9, could lead to arbitrary code execution, compromising the affected devices. Organizations using this router model should prioritize immediate patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82593
Severity
CRITICAL
CVSS
9.9
EPSS
0.51%

Original NVD Description

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.