Impact
The vulnerability is a stack-based buffer overflow in the sub_42B5A0 function of the /boafrm/formBridgeVlan component. Manipulating the submit-url argument allows a remote attacker to overflow the buffer, potentially enabling arbitrary code execution or system compromise. The weakness corresponds to CWE‑119 (Buffer Overflow) and CWE‑121 (Stack-based Buffer Overflow).
Affected Systems
D‑Link DWR‑M960 routers running firmware version 1.01.07 are affected.
Risk and Exploitability
The CVSS v3.1 score is 8.7, indicating high severity. The EPSS score is below 1%, suggesting a low yet non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote; a public exploit exists that targets the Bridge VLAN Configuration Endpoint via the web interface.
OpenCVE Enrichment