ZeroHour

CVE-2026-90692

moderate1

Stack Buffer Overflow in D-Link DIR-878 Dynamic DNS IPv6 Settings

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

A stack-based buffer overflow exists in the SetDynamicDNSIPv6Settings function of the Dynamic DNS IPv6 Settings component in D-Link DIR-878 routers running firmware 120B05. A remote attacker triggers it by supplying an oversized IPv6Address or Hostname argument to the affected management function, which the CVSS 4.0 vector indicates requires only low (likely authenticated-user level) privileges and no user interaction. Successful exploitation can overwrite stack memory, allowing the attacker to crash the device or potentially execute arbitrary code and fully compromise the router, with high impact to confidentiality, integrity, and availability. Home users and small offices running the DIR-878 on firmware 120B05 are the affected population. No public proof of concept is known and the flaw is not in CISA's KEV catalog, so exploitation status is none known.

What to do: Check D-Link's support site for a firmware update for the DIR-878 and apply it if one is available. If the device is end-of-life with no patch, disable remote/WAN administration so the management interface is reachable only from the LAN, and set a strong unique admin password since the attack path requires low privileges. Given the critical severity and the router's age, plan to replace unpatchable units with a supported model.

Affected
D-Link DIR-878120B05
Estimated exposure
moderatelikely low thousands of WAN-exposed management interfaces (order of 1k–10k devices), out of a total installed base that may be in the hundreds of thousands but… — Public scan engines typically show only a few thousand directly exposed web management interfaces for a given aging D-Link consumer router model, with the far larger installed base unreachable from the internet.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched remotely.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.