PT-2026-21415 · D Link · D-Link Dwr-M960

Lx-66-Lx

·

Published

2026-02-09

·

Updated

2026-02-27

·

CVE-2026-2926

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DWR-M960 version 1.01.07
Description A flaw exists in the D-Link DWR-M960 router, specifically within the LTE Configuration Endpoint. The issue resides in the sub 4237AC function of the /boafrm/formLteSetup component. Manipulation of the submit-url argument can lead to a stack-based buffer overflow, allowing for remote exploitation. The exploit has been published and may be used.
Recommendations Update to a newer version when available. As a temporary workaround, consider isolating the affected devices and monitoring for attacks.

Exploit

Fix

Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07503
CVE-2026-2926

Affected Products

D-Link Dwr-M960