CVE-2026-82595

A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 00:16

Updated : 2026-08-31 22:17


NVD link : CVE-2026-82595

Mitre link : CVE-2026-82595

CVE.ORG link : CVE-2026-82595


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')