Impact
The vulnerability exists in the sub_41914C function within the /boafrm/formWanConfigSetup component of the D-Link DWR‑M960 router’s firmware 1.01.07. An attacker can supply an overly long or otherwise malformed submit‑url argument to trigger a stack‑based buffer overflow. Because the web management interface is exposed over the WAN, the exploit can be performed remotely.
Affected Systems
Affected systems are D-Link DWR‑M960 Routers running firmware version 1.01.07. No other vendor or product versions are currently known to be impacted by this specific overflow. Users of newer firmware editions may be unaffected, but verification against the vendor’s release notes is recommended.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity issue, and the EPSS score of less than 1 % suggests a relatively low likelihood of immediate exploitation in the wild, though a publicly available exploit exists. Since the flaw resides in a remote‑accessible web interface, any authenticated administrator or a malicious actor with network visibility can potentially achieve arbitrary code execution, compromising the device and the networks it controls.
OpenCVE Enrichment