CVE-2026-2856
8.8D-Link · DWR-M960
A stack-based buffer overflow in the D-Link DWR-M960 Filter Configuration endpoint allows remote attackers to trigger memory corruption via the submit-url argument.
Executive summary
A stack-based buffer overflow vulnerability in D-Link DWR-M960 routers poses a high risk of remote code execution and system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring within the function sub_424AFC of the /boafrm/formFilter endpoint. The flaw is triggered by manipulating the submit-url argument, and the CVSS vector indicates that the attack requires low privileges (PR:L) to execute remotely.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its potential for total impact on system confidentiality, integrity, and availability. Successful exploitation allows a remote attacker to crash the device or potentially execute arbitrary code, which could lead to complete loss of control over the network gateway, data interception, and unauthorized access to internal resources.
Remediation
Immediate Action: Since a specific patch version is not currently provided by the vendor, administrators should restrict network access to the management interface of the DWR-M960 to trusted internal IP addresses only.
Proactive Monitoring: Monitor system logs and network traffic for unusual activity directed toward the /boafrm/formFilter endpoint, specifically looking for abnormally long or malformed URL parameters.
Compensating Controls: Implement a Web Application Firewall (WAF) or network-level access control list (ACL) to block access to the affected administrative endpoint from untrusted sources or public networks.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.
Analyst recommendation
Given the high severity of this vulnerability and the availability of a public proof-of-concept, users must treat this as an urgent security priority. Until D-Link releases a firmware update to address the overflow in the filter configuration module, ensure the device is not accessible from the internet and monitor for any signs of unauthorized configuration changes.
More D-Link CVEs
Sources
Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.