CVE-2026-4627Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-24: 4Technical Details · 2026-03-24: 403-24
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets8 URLs
Full discourse4 posts
  • dbugs@ptdbugs
    Disclosure

    D-Link DIR-825/DIR-825R NTP Service libdeuteron_modules.so handler_update_system_time os command injection CVE: CVE-2026-4627 PT-Identifier: PT-2026-27323 Vendor: D-link Product: DIR-825 CVSS: 8.6 Credits: 1935648903 (VulDB User) Description: A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4627 • https://vuldb.com/?id.352495 • https://vuldb.com/?ctiid.352495 • https://vuldb.com/?submit.775794 • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The text reports a newly disclosed command injection vulnerability in D‑Link DIR‑825 routers, detailing affected components and severity, but offers no PoC, exploitation tool, or mitigation guidance.

    00011116
    746 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4627 - D-Link - DIR-825 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4627-d-link-dir-825/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4627 #d-link #dir-825

    Post summary

    The tweet posts a CVE alert for D‑Link DIR‑825 with the CVE number and a link to an external article, but provides no PoC, exploit details, patch information, or false positive claim.

    0000077
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4627 A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the comp… https://www.cve.org/CVERecord?id=CVE-2026-4627

    Post summary

    The post announces CVE-2026-4627 affecting D‑Link DIR‑825 routers, outlining the impacted function and library, but contains no PoC, exploit code, or patch information.

    0000093
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4627 D-Link DIR-825 and DIR-825R NTP Service Remote OS Command Injection Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4627

    Post summary

    The text announces the discovery of a remote OS command injection vulnerability (CVE-2026-4627) in the NTP service of D‑Link DIR‑825 and DIR‑825R routers, linking to a vulnerability detail page.

    0000035
    4.0K followersView on X

Explore more