CVE-2026-2857
8.8D-Link · DWR-M960
A stack-based buffer overflow in the D-Link DWR-M960 port forwarding configuration allows remote attackers to trigger memory corruption via the submit-url parameter.
Executive summary
A critical stack-based buffer overflow vulnerability in D-Link DWR-M960 routers poses a severe risk of remote code execution and system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) located in the function sub_423E00 within the /boafrm/formPortFw file. An attacker with low-level privileges can trigger this memory corruption by manipulating the submit-url argument during port forwarding configuration.
Business impact
The exploitation of this vulnerability can result in a total loss of system integrity and availability, as it allows for arbitrary code execution on the networking hardware. Given the CVSS score of 8.8, this flaw represents a high risk to business operations, potentially enabling attackers to intercept network traffic, pivot into internal segments, or render the device unresponsive.
Remediation
Immediate Action: Contact D-Link support or monitor the official D-Link security portal for the release of a firmware update that addresses the vulnerability in the port forwarding configuration.
Proactive Monitoring: Monitor network traffic for anomalous requests directed at the /boafrm/formPortFw endpoint and audit configuration logs for unauthorized modifications to port forwarding rules.
Compensating Controls: Restrict access to the router administrative interface to trusted management IP addresses only and disable remote management features if they are not required for business operations.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists as documented in the linked GitHub repository.
Analyst recommendation
Due to the severity of this remote code execution vulnerability and the availability of a public proof-of-concept, users must treat this as a high-priority risk. Administrators should restrict management access to the affected devices immediately and apply forthcoming vendor patches as soon as they become available to prevent potential network compromise.
More D-Link CVEs
Sources
Originally found and disclosed by LX-66-LX (VulDB User), per the CVE Program record.