CVE-2026-90693
9.9D-Link · DIR-878
A stack-based buffer overflow in the SetWan3Settings function of the D-Link DIR-878 allows remote attackers to trigger memory corruption via manipulated WAN setting arguments.
Executive summary
A critical stack-based buffer overflow vulnerability in D-Link DIR-878 routers poses a severe risk of remote code execution and full system compromise.
Vulnerability
The vulnerability exists in the SetWan3Settings function, where improper handling of the Primary or Secondary arguments leads to a stack-based buffer overflow. This flaw requires low privileges to trigger, allowing an attacker to overwrite memory and potentially execute arbitrary code on the device.
Business impact
The vulnerability carries a CVSS score of 9.9, reflecting its critical potential for total system compromise. Successful exploitation could allow unauthorized actors to gain full control over the networking hardware, facilitating lateral movement within the internal network, data interception, or the permanent disruption of business-critical connectivity.
Remediation
Immediate Action: Given the lack of a confirmed vendor patch, administrators should restrict administrative access to the device to trusted management interfaces only and disable remote management features where possible.
Proactive Monitoring: Monitor network traffic for anomalous patterns directed at the router management interface and review system logs for signs of repeated crashes or unexpected service restarts.
Compensating Controls: Deploy a hardware or software firewall to block unauthorized access to the router management ports from untrusted networks, effectively isolating the vulnerable function from external reach.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical research provided by the vulnerability discovery report.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention, as it provides a direct vector for persistent device compromise. Because no patch is currently confirmed, organizations must prioritize network-level isolation of all affected D-Link DIR-878 devices to prevent remote exploitation until a vendor-supplied firmware update becomes available.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by AmaIIl (VulDB User), per the CVE Program record.
- VDB-403226 | D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow Vulnerability database entry
- VDB-403226 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-90693 | CVE Analysis and Report Third-party advisory
- Submit #915573 | D-Link Router FW120B05_decode Memory Corruption Third-party advisory
- Related
- dlink.com