CVE-2026-90692
9.9D-Link · DIR-878
A stack-based buffer overflow in the D-Link DIR-878 router allows remote authenticated attackers to execute arbitrary code by manipulating the IPv6Address or Hostname arguments.
Executive summary
A critical stack-based buffer overflow in D-Link DIR-878 firmware version 120B05 presents a severe risk of remote code execution for authenticated users.
Vulnerability
The vulnerability exists within the SetDynamicDNSIPv6Settings function of the Dynamic DNS IPv6 component. It is a stack-based buffer overflow triggered by improper input validation of the IPv6Address and Hostname parameters, requiring low-level authenticated access to exploit.
Business impact
The ability to trigger a stack-based buffer overflow allows an attacker to achieve remote code execution, potentially leading to a complete compromise of the network device. Given the CVSS score of 9.9, this vulnerability poses a critical threat to confidentiality, integrity, and availability, as unauthorized control over routing hardware can facilitate lateral movement within the corporate network and interception of traffic.
Remediation
Immediate Action: Contact D-Link support or check the official product page for firmware updates, as a specific patch version is not currently documented.
Proactive Monitoring: Monitor device logs for unusual administrative activity or repeated crashes of the Dynamic DNS service, which may indicate exploitation attempts.
Compensating Controls: Restrict administrative access to the router interface to trusted management IP addresses only and disable unnecessary Dynamic DNS features if they are not required for network operations.
Exploitation status
Public Exploit Available: Yes, a published PoC exists via the researcher write-up referenced in the CVE record.
Analyst recommendation
Due to the critical severity of this vulnerability and the availability of technical details, administrators must treat this as a high-priority item. If a firmware update from the vendor is unavailable, ensure that the management interface of the D-Link DIR-878 is not exposed to the public internet and restrict access to authorized personnel only to minimize the attack surface.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by AmaIIl (VulDB User), per the CVE Program record.
- VDB-403225 | D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow Vulnerability database entry
- VDB-403225 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-90692 | CVE Analysis and Report Third-party advisory
- Submit #915572 | D-Link Router FW120B05_decode Memory Corruption Third-party advisory
- Related
- dlink.com