CVE-2026-2854

8.8

D-Link · DWR-M960

A stack-based buffer overflow in the D-Link DWR-M960 NTP configuration endpoint allows remote attackers to trigger memory corruption via a manipulated submit-url argument.

Executive summary

A remote stack-based buffer overflow vulnerability in D-Link DWR-M960 routers poses a high risk of system compromise through memory corruption.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) located in the sub_4611CC function within the /boafrm/formNtp file. An authenticated attacker can trigger the overflow by providing a specially crafted input to the submit-url parameter of the NTP configuration endpoint.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for total loss of system integrity, availability, and confidentiality. Successful exploitation could allow a remote attacker to crash the device or execute arbitrary code, leading to unauthorized network access, potential lateral movement within the connected environment, and significant operational downtime.

Remediation

Immediate Action: Contact D-Link support or check the official product support page for firmware updates that address this buffer overflow, as no specific patch version is currently identified.

Proactive Monitoring: Monitor network traffic for unusual requests directed at the /boafrm/formNtp endpoint and review system logs for signs of device instability or unauthorized configuration changes.

Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses and implement Web Application Firewall (WAF) rules to inspect and sanitize input parameters sent to NTP configuration forms.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the linked GitHub repository.

Analyst recommendation

Given the high CVSS severity and the existence of a public proof-of-concept, this vulnerability represents a significant risk to network infrastructure. Administrators should prioritize isolating affected DWR-M960 units from public-facing segments until a firmware update is applied and verified. Immediate steps must be taken to minimize the attack surface by enforcing strict administrative access controls.

More D-Link CVEs

Sources

Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.