CVE-2026-2853
8.8D-Link · DWR-M960
A stack-based buffer overflow in the D-Link DWR-M960 System Log Configuration endpoint allows remote attackers to trigger memory corruption via the submit-url argument.
Executive summary
A critical stack-based buffer overflow vulnerability in D-Link DWR-M960 devices poses a significant risk of remote code execution or system crash.
Vulnerability
This vulnerability is a stack-based buffer overflow located in the sub_462E14 function of the /boafrm/formSysLog file. An attacker with low privileges can trigger this memory corruption by manipulating the submit-url argument remotely.
Business impact
Successful exploitation of this vulnerability can lead to a complete system compromise, allowing an attacker to execute arbitrary code or cause a permanent denial of service. Given the CVSS score of 8.8, this flaw represents a high risk to organizational network integrity, potentially facilitating lateral movement or unauthorized access to sensitive routing traffic.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should restrict access to the device management interface to trusted internal IP addresses only.
Proactive Monitoring: Review system logs for unusual activity surrounding the /boafrm/formSysLog endpoint and monitor for unexpected device reboots or service instability.
Compensating Controls: Implement strict firewall rules to block remote access to the web management console of the affected router from untrusted or external networks.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the research write-up at https://github.com/LX-66-LX/cve-new/issues/10.
Analyst recommendation
The presence of a public proof-of-concept combined with the potential for remote code execution makes this a high-priority issue. Network administrators should immediately isolate affected D-Link devices from the public internet and verify firmware status with the vendor to ensure any forthcoming security updates are applied as soon as they become available.
More D-Link CVEs
Sources
Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.