Impact
A stack‑based buffer overflow exists in the Wireless Access Control Endpoint of D‑Link DWR‑M960 firmware 1.01.07. By manipulating the submit‑url argument, an attacker can overflow a buffer in the sub_453140 routine, allowing arbitrary code execution from a remote host. This vulnerability is scored high on CVSS (8.7) and is listed under CWE‑119 and CWE‑121, indicating unchecked input handling and stack corruption.
Affected Systems
The affected system is D‑Link DWR‑M960 wireless router running firmware version 1.01.07. No other versions or models are mentioned in the CNA data.
Risk and Exploitability
The CVSS base score of 8.7 classifies this flaw as high severity; however, the EPSS score is reported as less than 1 %, implying a low probability of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog, and no official patch or workaround is referenced. Remote exploitation is possible via the publicly accessible web interface, and because the exploit has been disclosed, a determined attacker could leverage it if the device remains unpatched and reachable over the network.
OpenCVE Enrichment