D-Link DIR-825M Buffer Overflow Vulnerability in VPN Configuration Endpoint

Vulnerability

A buffer overflow vulnerability has been identified in the D-Link DIR-825M router, specifically in firmware version 1.1.12. The issue arises in the '/boafrm/formVpnConfigSetup' endpoint, within the 'sub_4151FC' function. The vulnerability is caused by improper input validation on the 'submit-url' parameter, which allows remote attackers to send oversized values. This exploitation can overwrite stack memory, potentially leading to application crashes, memory corruption, and arbitrary code execution on the device.

Impact

Exploitation of this vulnerability can cause the router to crash, making the management interface inaccessible. Additionally, it can be exploited to execute arbitrary code, allowing an attacker to gain full control over the device. This could lead to monitoring network traffic or using the router as a pivot point to attack other devices on the network.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/boafrm/formVpnConfigSetup' endpoint with an oversized 'submit-url' parameter. This can be done using a tool like Burp Repeater, without any authentication.

Added: Apr 28, 2026, 4:11 PM
Updated: Apr 28, 2026, 4:11 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
8.5
remediation
0.0
relevance
6.9
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.