Impact
The vulnerability in the D-Link DWR-M960 firmware 1.01.07 allows an attacker to send a crafted submit-url parameter to the /boafrm/formOpMode endpoint. The manipulation triggers a stack-based buffer overflow that can lead to arbitrary code execution on the device. By exploiting the flaw, an attacker can compromise the confidentiality, integrity, and availability of the device and potentially launch further attacks within the network.
Affected Systems
D-Link DWR-M960 router running firmware version 1.01.07. No other products or versions are listed as affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating a high severity. The EPSS score is below 1%, suggesting a low exploitation probability but not impossible. The vulnerability is not currently listed in the CISA KEV catalog, and no known public exploits are confirmed. The exploit can be initiated remotely, as stated in the description, meaning any host able to reach the vulnerable endpoint could potentially launch an attack.
OpenCVE Enrichment