PT-2026-21296 · D Link · D-Link Dwr-M960
Lx-66-Lx
·
Published
2026-02-09
·
Updated
2026-02-20
·
CVE-2026-2856
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-M960 version 1.01.07
Description
A flaw exists in the D-Link DWR-M960, specifically within the Filter Configuration Endpoint. The issue resides in the
sub 424AFC function of the /boafrm/formFilter file. Manipulation of the submit-url argument can lead to a stack-based buffer overflow. This issue can be exploited remotely. The exploit has been publicly released.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Filter Configuration Endpoint.
Exploit
Fix
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dwr-M960