A critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-878 router's IPv6 Dynamic DNS settings handler can be triggered remotely by an authenticated attacker.
What Is It
VulDB reported a vulnerability in D-Link DIR-878 firmware 120B05 affecting the SetDynamicDNSIPv6Settings function within the Dynamic DNS IPv6 Settings component. Manipulation of the IPv6Address/Hostname argument results in a stack-based buffer overflow. The attack may be launched remotely.
The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow).
Why It Matters
The CVSS 3.1 base score is 9.9 CRITICAL, with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Network attack vector, low attack complexity, low privileges required, and no user interaction. The scope is marked CHANGED, and confidentiality, integrity, and availability impacts are all HIGH, reflected in the secondary CVSS 4.0 score of 9.4 CRITICAL, which likewise rates subsequent-system confidentiality, integrity, and availability impacts as HIGH.
A stack overflow reachable over the network on an edge device places the router's control plane at risk. Only low-level privileges are needed to reach the vulnerable function, so credentials obtained through default passwords or reuse would be sufficient.
What's Vulnerable
- Vendor: D-Link
- Product: DIR-878 (
cpe:2.3:h:d-link:dir-878) - Affected version: 120B05
- Affected module: Dynamic DNS IPv6 Settings
- Vulnerable function:
SetDynamicDNSIPv6Settings
No other versions or models are listed as affected in the supplied record.
Patch Status
No fixed version, vendor advisory, or remediation guidance is present in the supplied data. The record status is "Received" (published 2026-09-14), meaning NVD analysis is not yet complete. CVE-2026-90692 does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied material, and no confirmation of active exploitation is available. The only vendor reference provided is D-Link's general website; operators should check there directly for firmware updates.
Sources
- NVD, CVE-2026-90692: https://nvd.nist.gov/vuln/detail/CVE-2026-90692
- VulDB, CVE-2026-90692: https://vuldb.com/cve/CVE-2026-90692
- VulDB, Entry 403225: https://vuldb.com/vuln/403225
- VulDB, Entry 403225 CTI: https://vuldb.com/vuln/403225/cti
- VulDB, Submission 915572: https://vuldb.com/submit/915572
- Researcher advisory (Amalll-Sec): https://github.com/Amalll-Sec/router-vulnerability-research/blob/main/advisories/d-link/dir-878/SetDynamicDNSIPv6Settings/README.md
- D-Link: https://www.dlink.com/