HIGH🇵🇱 Wersja polska

CVE-2026-7068

CVSS 7.4v4.0pub. 2026-04-27upd. 2026-04-30

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dir 825

    HW
    Dlink
    all versions
  • Dlink Dir 825 Firmware

    OS
    Dlink
    3.00b32
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2020-29557CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w D-Link DIR-825 umożliwiający RCE bez uwierzytelnienia

CVE-2019-16920CRITICAL9.8⚠ KEVPL ✓same product

D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI

CVE-2022-47035CRITICAL9.8PL ✓same product

Buffer Overflow w D-Link DIR-825 umożliwiający zdalne wykonanie kodu

CVE-2021-46442CRITICAL9.8PL ✓same product

Auth Bypass w D-Link DIR-825 G1 — nieautoryzowany dostęp do firmware i konfiguracji

CVE-2026-7069HIGH7.3same product

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping ...