PT-2026-21296 · D Link · D-Link Dwr-M960

Lx-66-Lx

·

Published

2026-02-09

·

Updated

2026-02-20

·

CVE-2026-2856

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DWR-M960 version 1.01.07
Description A flaw exists in the D-Link DWR-M960, specifically within the Filter Configuration Endpoint. The issue resides in the sub 424AFC function of the /boafrm/formFilter file. Manipulation of the submit-url argument can lead to a stack-based buffer overflow. This issue can be exploited remotely. The exploit has been publicly released.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Filter Configuration Endpoint.

Exploit

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06282
CVE-2026-2856

Affected Products

D-Link Dwr-M960