Impact
The vulnerability resides in the sub_457C5C function within the /boafrm/formWsc file of D-Link DWR‑M960 firmware 1.01.07. By manipulating the save_apply argument, an attacker can trigger a stack‑based buffer overflow, which may lead to remote code execution. This weakness is classified as both CWE‑119 and CWE‑121, indicating unsafe handling of untrusted input and stack manipulation errors.
Affected Systems
The affected product is the D‑Link DWR‑M960 router running firmware version 1.01.07. No other versions or models are currently listed as vulnerable, and only this firmware variant appears in the public references.
Risk and Exploitability
The CVSS score of 8.7 marks this as a high‑severity flaw, while the EPSS score is less than 1% indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely via the web interface, and the publicly disclosed exploit suggests that it could be weaponized in realistic threat environments.
OpenCVE Enrichment