CVE-2026-2856

8.8

D-Link · DWR-M960

A stack-based buffer overflow in the D-Link DWR-M960 Filter Configuration endpoint allows remote attackers to trigger memory corruption via the submit-url argument.

Executive summary

A stack-based buffer overflow vulnerability in D-Link DWR-M960 routers poses a high risk of remote code execution and system compromise.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the function sub_424AFC of the /boafrm/formFilter endpoint. The flaw is triggered by manipulating the submit-url argument, and the CVSS vector indicates that the attack requires low privileges (PR:L) to execute remotely.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for total impact on system confidentiality, integrity, and availability. Successful exploitation allows a remote attacker to crash the device or potentially execute arbitrary code, which could lead to complete loss of control over the network gateway, data interception, and unauthorized access to internal resources.

Remediation

Immediate Action: Since a specific patch version is not currently provided by the vendor, administrators should restrict network access to the management interface of the DWR-M960 to trusted internal IP addresses only.

Proactive Monitoring: Monitor system logs and network traffic for unusual activity directed toward the /boafrm/formFilter endpoint, specifically looking for abnormally long or malformed URL parameters.

Compensating Controls: Implement a Web Application Firewall (WAF) or network-level access control list (ACL) to block access to the affected administrative endpoint from untrusted sources or public networks.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.

Analyst recommendation

Given the high severity of this vulnerability and the availability of a public proof-of-concept, users must treat this as an urgent security priority. Until D-Link releases a firmware update to address the overflow in the filter configuration module, ensure the device is not accessible from the internet and monitor for any signs of unauthorized configuration changes.

More D-Link CVEs

Sources

Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.