Impact
A stack-based buffer overflow exists in the SetWan3Settings function of the D-Link DIR-878 120B05 router firmware. By manipulating the Primary/Secondary argument, an attacker can cause an overflow on the call stack. Remote exploitation is possible, meaning an attacker can send crafted data from outside the network to trigger the overflow and gain arbitrary code execution on the device, compromising network confidentiality, integrity, and availability. The flaw is associated with CWE-119 and CWE-121 weaknesses.
Affected Systems
The vulnerability affects D-Link DIR-878 routers running firmware version 120B05. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity. The EPSS score is less than 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in CISA KEV, which does not alter the high potential for exploitation. The likely attack vector is remote network access to the router’s WAN interface, requiring only network connectivity and no prior local privileges. Once exploited, the attacker would achieve full control over the routing device.
OpenCVE Enrichment