CVE-2026-7288: D-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow
A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7288?
CVE-2026-7288 is classified as a high severity vulnerability due to the potential for remote exploitation leading to a buffer overflow.
How do I fix CVE-2026-7288?
To fix CVE-2026-7288, update the D-Link DIR-825M router to the latest firmware version beyond 1.1.12.
What are the potential impacts of CVE-2026-7288?
CVE-2026-7288 can allow an attacker to execute arbitrary code remotely due to the buffer overflow vulnerability.
Which versions of D-Link DIR-825M are affected by CVE-2026-7288?
CVE-2026-7288 affects D-Link DIR-825M version 1.1.12.
Can CVE-2026-7288 be exploited over the network?
Yes, CVE-2026-7288 can be exploited remotely over the network, making it particularly dangerous.