CVE-2026-82593 is a stack-based buffer overflow in the LTE Module Firmware Upgrade component of D-Link DIR-825M firmware 1.1.8. The vulnerable upgrade-request handler fails to safely bound the fota_url argument before copying or processing it on the stack. An authenticated remote attacker can submit a crafted value to corrupt stack memory. Public exploit code has been reported.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVSS 9.9 stack-based buffer overflow in the D-Link DIR-825M LTE firmware-update module. An authenticated attacker can supply a crafted fota_url value to corrupt memory and execute arbitrary code with elevated router privileges.
A remotely exploitable stack-based buffer overflow in the LTE Module Firmware Upgrade component of D-Link DIR-825M firmware version 1.1.8. The fota_url argument can be manipulated in the formLtefotaUpgradeFibocom handler.
A remotely exploitable stack-based buffer overflow in the LTE Module Firmware Upgrade component of D-Link DIR-825M firmware 1.1.8. Manipulation of the fota_url argument in /boafrm/formLtefotaUpgradeFibocom, within sub_41802C, triggers the flaw. The listed CVSS v3.1 vector indicates network reachability, low attack complexity, low privileges required, no user interaction, scope change, and high confidentiality, integrity, and availability impact.
Critical stack-based buffer overflow in the LTE Module Firmware Upgrade handler of D-Link DIR-825M firmware 1.1.8. The published assessment states that network exploitation requires low privileges and no user interaction.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.