Description
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Published: 2026-08-30
Score: 5.3 Medium
EPSS: 1.3% Low
KEV: No
Impact: Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

The flaw resides in the sub_456CF4 function of the component accessed via /boafrm/formSysCmd. A manipulated sysCmd argument allows an attacker to inject arbitrary operating‑system commands; the injected input is directly concatenated into a shell command without proper validation. This enables code execution, which could compromise the router’s confidentiality, integrity, and availability. The weakness is classified as command injection (CWE‑74) and OS command injection (CWE‑77).

Affected Systems

The vulnerability affects the D‑Link DIR‑825M router running firmware 1.1.8. No other affected versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access to the router’s management interface, and the exploit has been made public, making it likely that attackers with network access could attempt exploitation.

Generated by OpenCVE AI on August 31, 2026 at 14:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official firmware update for the D‑Link DIR‑825M that fixes the command injection vulnerability.
  • Disable remote management or the formSysCmd feature in the router’s configuration interface, if possible.
  • Block external access to the /boafrm/formSysCmd endpoint using the router’s firewall or network segmentation tools.

Generated by OpenCVE AI on August 31, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Title D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection
First Time appeared D-link
D-link dir-825m
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:d-link:dir-825m:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-825m
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T22:04:06.409Z

Reserved: 2026-08-30T06:23:02.334Z

Link: CVE-2026-82595

cve-icon Vulnrichment

Updated: 2026-08-31T21:50:28.718Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T00:16:41.980

Modified: 2026-08-31T22:17:26.127

Link: CVE-2026-82595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T14:45:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')