CVE-2026-82680: D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write
A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /loadfile.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the severity vector indicates that low privileges are required. No user interaction is required.
Which systems are known to be affected?
The affected product identified in the available data is D-Link DSM-G600 version 1.01. The issue is associated with multipart handling in the /load_file.cgi endpoint.
How serious could a successful exploit be?
A successful out-of-bounds write could affect confidentiality, integrity, and availability at high impact levels. Public exploit availability is reported, increasing the likelihood of attempted attacks.