← All Advisories

D-Link DIR-825M System Command Endpoint Passes sysCmd Unsanitized to the Shell; Public Exploit Available

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-82595

Key Details

CVECVE-2026-82595
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-08-31
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is low.
Classified asCWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'))

What to Know

A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-82595
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-82595