← back
CVE-2026-7068highCWE-119CWE-120

D-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.7epss 1.9%
exploitation probability
1.9%top 23% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DIR-825
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.