ZeroHour

CVE-2026-90680

moderate

Stack Buffer Overflow in D-Link DIR-823G HNAP1 SetStaticRouteSettings

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

A remotely exploitable stack-based buffer overflow exists in the D-Link DIR-823G wireless router (firmware 1.0.2B05_20181207) within the HNAP1 web management component, specifically in the strcpy call inside the /HNAP1/SetStaticRouteSettings handler. An attacker triggers the flaw by sending an oversized value in the PAddress, SubnetMask, or Gateway arguments of a crafted SetStaticRouteSettings request, overwriting the stack and potentially gaining full control of the router (code execution with root-level privileges on the embedded device). The CVSS 4.0 base score is 9.4 (critical), with the attack requiring network access, low complexity, and only low privileges (a valid or bypassable HNAP login on many affected units). Owners of DIR-823G routers running the stated firmware are affected, particularly units reachable from the WAN if remote HNAP management is enabled. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not known to be occurring in the wild.

What to do: Update the DIR-823G to the latest firmware available from D-Link's regional support site, as this model has a history of similar HNAP1 flaws. Disable remote/WAN-side management and block port 80/443/8443 HNAP access from the internet so the SetStaticRouteSettings endpoint is only reachable from the trusted LAN. Review the router's static route table and admin accounts for unexpected entries that could indicate prior tampering, and replace the device if it is end-of-support and no patched firmware is offered.

Affected
D-Link DIR-823G
Estimated exposure
moderateThousands to low tens of thousands of internet-exposed devices; total deployed base plausibly in the hundreds of thousands — The DIR-823G is a budget AC1200 router sold primarily in China and Asia-Pacific markets, and public scan services typically show low-thousands counts of D-Link HNAP endpoints reachable online, most others exposed only on the LAN.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.