Executive brief
The D-Link DSM-G600 is a network storage device. A memory corruption vulnerability in its web interface (/load_file.cgi) allows an attacker to write data outside allocated memory bounds, potentially leading to device compromise, data corruption, or complete system failure without requiring authentication.
Technical details
The vulnerability is an out-of-bounds write flaw in the Multipart Handler component of the D-Link DSM-G600's /load_file.cgi endpoint. The weakness allows an attacker to manipulate input to the web interface and write to memory regions beyond the intended buffer, leading to memory corruption. The attack vector is network-based and does not require prior authentication. Successful exploitation can result in arbitrary code execution or system crash. A public exploit is available.
Affected products
- D-Link DSM-G600 1.01
Timeline
- 2026-08-31: disclosed