CVE-2026-90680
moderateStack Buffer Overflow in D-Link DIR-823G HNAP1 SetStaticRouteSettings
A remotely exploitable stack-based buffer overflow exists in the D-Link DIR-823G wireless router (firmware 1.0.2B05_20181207) within the HNAP1 web management component, specifically in the strcpy call inside the /HNAP1/SetStaticRouteSettings handler. An attacker triggers the flaw by sending an oversized value in the PAddress, SubnetMask, or Gateway arguments of a crafted SetStaticRouteSettings request, overwriting the stack and potentially gaining full control of the router (code execution with root-level privileges on the embedded device). The CVSS 4.0 base score is 9.4 (critical), with the attack requiring network access, low complexity, and only low privileges (a valid or bypassable HNAP login on many affected units). Owners of DIR-823G routers running the stated firmware are affected, particularly units reachable from the WAN if remote HNAP management is enabled. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not known to be occurring in the wild.
What to do: Update the DIR-823G to the latest firmware available from D-Link's regional support site, as this model has a history of similar HNAP1 flaws. Disable remote/WAN-side management and block port 80/443/8443 HNAP access from the internet so the SetStaticRouteSettings endpoint is only reachable from the trusted LAN. Review the router's static route table and admin accounts for unexpected entries that could indicate prior tampering, and replace the device if it is end-of-support and no patched firmware is offered.
| D-Link DIR-823G | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
- Weakness
- CWE-119, CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.