Impact
A stack‑based buffer overflow exists in the D‑Link DIR‑895L firmware’s udhcpcd component, specifically in the sendOffer/sendACK functions of serverpacket.c. The flaw is triggered by specially crafted DHCP packets and can be exploited from within the local network. Once triggered, a malicious client can cause the router to execute arbitrary code or crash.
Affected Systems
The vulnerability affects D‑Link routers of model DIR‑895L running firmware version A1_102b07. No other products or firmware dates are listed.
Risk and Exploitability
The CVSS score of 9.4 indicates high severity, although the EPSS value is not available and the flaw is not listed in the CISA KEV catalog. The attack can be performed from any device on the local network and an exploit has already been published, so the likelihood of usage is high in environments that have not applied an update.
OpenCVE Enrichment