ZeroHour

CVE-2026-90693

moderate

Stack buffer overflow in D-Link DIR-878 WAN settings allows remote code execution

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

A stack-based buffer overflow (CWE-121/119) exists in the SetWan3Settings function of the WAN Settings component in D-Link DIR-878 routers running firmware 120B05. A remote attacker who has authenticated with low privileges can trigger the flaw by supplying an oversized value in the Primary/Secondary arguments of a WAN settings request, overwriting stack memory. Successful exploitation can crash the device or yield arbitrary code execution with full control of the router, enabling interception or manipulation of routed traffic and use of the device as a pivot into the home or small-office network. Only D-Link DIR-878 units on firmware 120B05 are confirmed affected, and the CVSS 4.0 score of 9.4 (critical) reflects high impact on confidentiality, integrity, and availability. No public proof-of-concept or in-the-wild exploitation is known, and the flaw is not on the CISA Known Exploited Vulnerabilities list.

What to do: Check D-Link's security advisories for a fixed DIR-878 firmware; if version 120B05 is no longer supported, plan to retire and replace the unit. In the interim, disable remote/WAN-side management, restrict the admin interface to the LAN or a VPN, and change default credentials since exploitation requires low-privilege authentication. Watch for unexplained reboots or unexpected changes to WAN settings, which would indicate tampering.

Affected
D-Link DIR-878120B05
Estimated exposure
moderatelow thousands of internet-exposed admin interfaces; total installed base plausibly in the tens of thousands of devices — Estimated from typical public internet-scan (Shodan/Censys-style) counts for legacy D-Link SOHO router web interfaces and the model's age and discontinued status; no official deployment figure is available, so this is clearly an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the attack is possible.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.