Description
A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_425FF8 of the file /boafrm/formFirewallAdv of the component Advanced Firewall Configuration Endpoint. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-02-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via stack-based buffer overflow
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow (CWE-119/CWE-121) exists in the Advanced Firewall Configuration Endpoint of the D-Link DWR-M960 when the submit‑url argument is processed by the sub_425FF8 function. The flaw allows a remote attacker to send a crafted request that overflows the stack, enabling arbitrary code execution on the device. This can compromise the device’s confidentiality, integrity, and availability, and provides the attacker with full control of the router or firewall over the network.

Affected Systems

The vulnerability is limited to the D-Link DWR-M960 model running firmware version 1.01.07. No other firmware versions are listed as affected.

Risk and Exploitability

The Common Vulnerability Scoring System assigns a score of 8.7, indicating a high severity issue. The Exploit Prediction Scoring System score is less than 1%, suggesting a low probability of exploitation, though the flaw has been publicly disclosed and the exploit code is available. The vulnerability is not present in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw remotely by sending a malicious request to the /boafrm/formFirewallAdv endpoint, provided the Advanced Firewall Configuration Interface is enabled and accessible over the network.

Generated by OpenCVE AI on April 18, 2026 at 11:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware update that patches the sub_425FF8 overflow or apply any vendor-supplied hotfix that addresses the issue.
  • Disable or restrict remote access to the Advanced Firewall Configuration Endpoint, for example by limiting the Web UI to trusted IP ranges or IP whitelisting.
  • If an update is not immediately available, enforce strong authentication, review user privileges, and closely monitor logs for suspicious requests to /boafrm/formFirewallAdv to detect potential exploitation attempts.

Generated by OpenCVE AI on April 18, 2026 at 11:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dwr-m960
Dlink dwr-m960 Firmware
CPEs cpe:2.3:h:dlink:dwr-m960:b1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m960_firmware:1.01.07:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dwr-m960
Dlink dwr-m960 Firmware

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m960
Vendors & Products D-link
D-link dwr-m960

Sat, 21 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_425FF8 of the file /boafrm/formFirewallAdv of the component Advanced Firewall Configuration Endpoint. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Title D-Link DWR-M960 Advanced Firewall Configuration Endpoint formFirewallAdv sub_425FF8 stack-based overflow
Weaknesses CWE-119
CWE-121
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dwr-m960
Dlink Dwr-m960 Dwr-m960 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T19:24:16.120Z

Reserved: 2026-02-20T16:59:05.122Z

Link: CVE-2026-2881

cve-icon Vulnrichment

Updated: 2026-02-23T19:24:10.272Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-21T20:16:39.067

Modified: 2026-02-23T20:25:52.360

Link: CVE-2026-2881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T11:30:44Z

Weaknesses