A reportedly critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-823G's HNAP1 static route handler would let a remote, low-privileged attacker corrupt memory through crafted routing parameters. The record has not yet completed NVD analysis, so the details below reflect the reporting party's claims rather than independently confirmed findings.
What Is It
According to the submitted advisory, a security flaw exists in D-Link DIR-823G firmware 1.0.2B05_20181207. The element identified as impacted is the strcpy function in the file /HNAP1/SetStaticRouteSettings, part of the HNAP1 component. Manipulation of the PAddress, SubnetMask, or Gateway arguments is reported to result in a stack-based buffer overflow, and the attack is described as launchable remotely.
The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow). It was published to NVD on 2026-09-14 by VulDB as the CNA, and currently carries a vulnerability status of "Received"; meaning NVD has ingested the submission but has not yet performed its own analysis or enrichment. The affected-version data, weakness mapping, and severity metrics therefore all originate from the CNA at this stage and may change.
Why It Matters
The CNA-assigned CVSS 3.1 base score is 9.9 (CRITICAL), vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. If that vector holds up under analysis, it is about as bad as it gets for an embedded device: network attack vector, low attack complexity, no user interaction, and only low privileges required. The scope is rated CHANGED, with HIGH impact to confidentiality, integrity, and availability; implying successful exploitation would reach beyond the vulnerable component itself.
The CVSS 4.0 secondary score is 9.4 (CRITICAL), which likewise rates all vulnerable-system and subsequent-system impacts as HIGH. The CVSS 2.0 score is 9.0. These are provisional pending NVD's own scoring, which has historically diverged from CNA submissions on scope and privilege assumptions.
No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation or federally mandated remediation deadline associated with it in the source material. Absence of a KEV entry is not evidence that exploitation is not occurring; only that none has been catalogued.
What's Vulnerable
Per the CNA submission:
- Vendor: D-Link
- Product: DIR-823G
- Affected version: 1.0.2B05_20181207
- Affected module: HNAP1
- CPE:
cpe:2.3:h:d-link:dir-823g:*:*:*:*:*:*:*:*
Note that the CPE as supplied uses a wildcard for the version field, which is broader than the single firmware build named as affected. Whether other builds are impacted has not been established in the source material.
Patch Status
The supplied source material does not identify a patch, fixed firmware version, or vendor advisory for this issue. The only vendor reference provided is D-Link's main website, and there is no indication in the material that D-Link has acknowledged the report. Operators running DIR-823G 1.0.2B05_20181207 should check directly with D-Link for firmware guidance and restrict network reachability of the HNAP1 interface in the meantime; a defensible precaution regardless of how the report is ultimately adjudicated, given that the DIR-823G is an end-of-life-era consumer device.
Sources
- NVD, CVE-2026-90680: https://nvd.nist.gov/vuln/detail/CVE-2026-90680
- VulDB, CVE-2026-90680: https://vuldb.com/cve/CVE-2026-90680
- VulDB, Vulnerability 403213: https://vuldb.com/vuln/403213
- VulDB, Threat Intelligence (403213): https://vuldb.com/vuln/403213/cti
- VulDB, Submission 914902: https://vuldb.com/submit/914902
- Researcher advisory (Amalll-Sec): https://github.com/Amalll-Sec/router-vulnerability-research/blob/main/advisories/d-link/dir-823g/SetStaticRouteSettings/README.md
- D-Link: https://www.dlink.com/