Impact
A stack-based buffer overflow exists in the sub_46725C function of the /boafrm/formDiskFormat component on the D‑Link DIR‑825M. The vulnerability is triggered by manipulating the ‘partition’ argument, which allows an attacker to overwrite the return address on the stack and execute arbitrary code, potentially giving full control over the router’s firmware. The CVE description states that the attack can be executed remotely and that an exploit is public, but it does not specify whether authentication is required. Based on the nature of a disk‑formatting endpoint and the usual management interface, it is inferred that the attack involves sending crafted requests to the router’s HTTP endpoint, although the exact access prerequisites remain unspecified.
Affected Systems
The flaw is limited to the D‑Link DIR‑825M model running firmware version 1.1.8. No other firmware revisions are listed as affected in the CVE record or in the external references. The vulnerability is associated with the router’s Disk Formatting Handler component.
Risk and Exploitability
The CVSS v3 score of 9.4 indicates a critical severity. An EPSS score is not available, but the publicly available exploit increases the likelihood of real‑world attacks. Since the router’s HTTP/HTTPS ports are exposed to the internet, remote attackers can reach the vulnerable endpoint from outside the network without any explicitly stated authentication. The lack of a KEV listing does not reduce the urgency of remediation, as the attack surface and potential impact remain high.
OpenCVE Enrichment