Impact
This vulnerability is a stack‑based buffer overflow in the SetDynamicDNSIPv6Settings component on D‑Link DIR‑878 firmware 120B05. An attacker can supply an oversized IPv6 address or hostname argument, causing the firmware to overrun a buffer on the stack. The description states the attack may be launched remotely, allowing a malformed request to trigger overflow and execute arbitrary code in the router’s context.
Affected Systems
The flaw impacts D‑Link DIR‑878 firmware 120B05. Other firmware revisions are not reported as affected at this time.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.4, indicating critical severity, and the EPSS score is <1%. It is not listed in the CISA KEV catalog. The attack may be launched remotely through the router’s management interface by sending a crafted IPv6 dynamic DNS configuration request. Based on the description, it is inferred that exploitation could allow an attacker to arbitrarily execute code on the device, potentially giving them elevated control over the network infrastructure.
OpenCVE Enrichment