CVE-2026-7068

8.8

D-Link · DIR-825

A stack-based buffer overflow in the nmbd component of D-Link DIR-825 version 3.00b32 allows local network attackers to potentially execute arbitrary code.

Executive summary

A critical buffer overflow vulnerability in D-Link DIR-825 devices poses a severe risk of memory corruption and potential code execution for local network users.

Vulnerability

This vulnerability is a buffer overflow within the NMBD_process function of the nmbd component, which can be triggered by an unauthenticated attacker located on the local network.

Business impact

The exploitation of this memory corruption vulnerability allows an attacker to achieve total technical impact, potentially leading to unauthorized control of the affected networking hardware. Given the CVSS score of 8.8, this flaw represents a significant risk to network integrity. Because the device is no longer supported by the vendor, organizations relying on this hardware face permanent exposure to this flaw, which may facilitate lateral movement or network interception within the local segment.

Remediation

Immediate Action: As the affected hardware is no longer supported by D-Link, the most effective remediation is to retire and replace the device with a modern, vendor-supported alternative.

Proactive Monitoring: Monitor local network traffic for anomalous NetBIOS Name Service requests or unusual spikes in traffic directed toward the nmbd service.

Compensating Controls: Isolate the affected devices on a restricted management VLAN or behind a robust firewall to prevent unauthorized local network access to the vulnerable service.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via the technical write-up referenced by the CVE record.

Analyst recommendation

Due to the end-of-life status of the D-Link DIR-825, no official patch will be released to address this vulnerability. Security teams must prioritize the immediate decommissioning of these devices to eliminate the risk of remote code execution. Continued operation of this hardware within a production environment is strongly discouraged and presents an unacceptable security posture for the organization.

More D-Link CVEs

Sources

Originally found and disclosed by tian (VulDB User), per the CVE Program record.