CVE-2026-2855
8.8D-Link · DWR-M960
A stack-based buffer overflow in the D-Link DWR-M960 DDNS Settings Handler allows remote attackers to trigger memory corruption via the submit-url argument.
Executive summary
A stack-based buffer overflow in the D-Link DWR-M960 router enables remote code execution and system compromise via the DDNS settings interface.
Vulnerability
The vulnerability exists within the sub_4648F0 function of the /boafrm/formDdns file, where improper handling of the submit-url argument leads to a stack-based buffer overflow. This flaw is reachable by an authenticated user, as indicated by the CVSS vector PR:L, and allows for remote exploitation.
Business impact
The exploitation of this vulnerability can lead to a complete compromise of the affected D-Link router, granting the attacker control over network traffic and administrative functions. With a CVSS score of 8.8, this flaw poses a high risk to business continuity and data integrity. Unauthorized access at this level may facilitate lateral movement into protected internal segments, significantly increasing the potential for further breach activities.
Remediation
Immediate Action: Given that a specific patch version is currently unknown, users should immediately restrict access to the web management interface of the DWR-M960 to trusted internal IP addresses only.
Proactive Monitoring: Security teams should monitor firewall and device logs for suspicious POST requests directed at the /boafrm/formDdns endpoint that contain unusually long or malformed submit-url parameter strings.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an intrusion detection rule to inspect and block traffic containing excessive payloads directed at the DDNS configuration parameters.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the security researcher's submission via GitHub.
Analyst recommendation
Due to the high severity of this stack-based buffer overflow and the availability of a public proof-of-concept, organizations must treat this vulnerability with urgency. Until D-Link provides an official firmware update, administrators should isolate the management interface from the public internet and verify that no unauthorized users have access to the device configuration. Continuous monitoring of device logs is essential to detect any attempts to trigger this memory corruption flaw.
More D-Link CVEs
Sources
Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.
- VDB-347094 | D-Link DWR-M960 DDNS Settings formDdns sub_4648F0 stack-based overflow Vulnerability database entry
- VDB-347094 | CTI Indicators (IOB, IOC, IOA)
- Submit #754458 | D-Link DWR-M960 V1.0.07 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com