CVE-2026-90692

9.9

D-Link · DIR-878

A stack-based buffer overflow in the D-Link DIR-878 router allows remote authenticated attackers to execute arbitrary code by manipulating the IPv6Address or Hostname arguments.

Executive summary

A critical stack-based buffer overflow in D-Link DIR-878 firmware version 120B05 presents a severe risk of remote code execution for authenticated users.

Vulnerability

The vulnerability exists within the SetDynamicDNSIPv6Settings function of the Dynamic DNS IPv6 component. It is a stack-based buffer overflow triggered by improper input validation of the IPv6Address and Hostname parameters, requiring low-level authenticated access to exploit.

Business impact

The ability to trigger a stack-based buffer overflow allows an attacker to achieve remote code execution, potentially leading to a complete compromise of the network device. Given the CVSS score of 9.9, this vulnerability poses a critical threat to confidentiality, integrity, and availability, as unauthorized control over routing hardware can facilitate lateral movement within the corporate network and interception of traffic.

Remediation

Immediate Action: Contact D-Link support or check the official product page for firmware updates, as a specific patch version is not currently documented.

Proactive Monitoring: Monitor device logs for unusual administrative activity or repeated crashes of the Dynamic DNS service, which may indicate exploitation attempts.

Compensating Controls: Restrict administrative access to the router interface to trusted management IP addresses only and disable unnecessary Dynamic DNS features if they are not required for network operations.

Exploitation status

Public Exploit Available: Yes, a published PoC exists via the researcher write-up referenced in the CVE record.

Analyst recommendation

Due to the critical severity of this vulnerability and the availability of technical details, administrators must treat this as a high-priority item. If a firmware update from the vendor is unavailable, ensure that the management interface of the D-Link DIR-878 is not exposed to the public internet and restrict access to authorized personnel only to minimize the attack surface.

More D-Link CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by AmaIIl (VulDB User), per the CVE Program record.