Impact
This vulnerability is a stack-based buffer overflow in the app.cgi handler of D-Link DWR‑M961 routers. An attacker can submit an excessively long string to the netAcc.addlist[].name parameter, exceeding the buffer limit and overwriting adjacent memory. The overflow can be used to inject and execute arbitrary shell commands or trigger a device crash. The flaw falls under CWE‑120 and can compromise confidentiality, integrity, and availability by allowing remote code execution or denial of service, respectively.
Affected Systems
The affected devices are D-Link DWR‑M961 routers, specifically hardware revision C1 running firmware version 1.1.2_C1_202602110044. These models are distributed by D-Link Corporation and are configured with a web interface that exposes the vulnerable app.cgi URL. Any unit running this firmware and reachable over an IP network is vulnerable.
Risk and Exploitability
The vulnerability received a CVSS score of 9.3, classifying it as Critical. While the EPSS score is not available, the lack of a KEV listing does not reduce its risk, as the condition can be exploited remotely once the device is reachable. The buffer overflow can be triggered via an unauthenticated HTTP request, making it trivial for an attacker to gain execution without additional credentials. Given the high severity and remote attack vector, operators must act promptly.
OpenCVE Enrichment