Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-90692 2026-09-14

CVE-2026-90692: Critical Stack Overflow in D-Link DIR-878 Dynamic DNS Handler

"A critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-878 router's IPv6 Dynamic DNS settings handler can be triggered remotely by an authenticated attacker."

A critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-878 router's IPv6 Dynamic DNS settings handler can be triggered remotely by an authenticated attacker.

What Is It

VulDB reported a vulnerability in D-Link DIR-878 firmware 120B05 affecting the SetDynamicDNSIPv6Settings function within the Dynamic DNS IPv6 Settings component. Manipulation of the IPv6Address/Hostname argument results in a stack-based buffer overflow. The attack may be launched remotely.

The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow).

Why It Matters

The CVSS 3.1 base score is 9.9 CRITICAL, with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Network attack vector, low attack complexity, low privileges required, and no user interaction. The scope is marked CHANGED, and confidentiality, integrity, and availability impacts are all HIGH, reflected in the secondary CVSS 4.0 score of 9.4 CRITICAL, which likewise rates subsequent-system confidentiality, integrity, and availability impacts as HIGH.

A stack overflow reachable over the network on an edge device places the router's control plane at risk. Only low-level privileges are needed to reach the vulnerable function, so credentials obtained through default passwords or reuse would be sufficient.

What's Vulnerable

No other versions or models are listed as affected in the supplied record.

Patch Status

No fixed version, vendor advisory, or remediation guidance is present in the supplied data. The record status is "Received" (published 2026-09-14), meaning NVD analysis is not yet complete. CVE-2026-90692 does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied material, and no confirmation of active exploitation is available. The only vendor reference provided is D-Link's general website; operators should check there directly for firmware updates.

Sources