A critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-878 router's WAN Settings handler could allow remote, low-privilege attackers to corrupt memory and potentially compromise the device.
What Is It
CVE-2026-90693 is a stack-based buffer overflow in the SetWan3Settings function of the WAN Settings component on D-Link DIR-878 firmware 120B05. According to the published record, manipulation of the Primary/Secondary argument triggers the overflow, and remote exploitation is reported to be possible.
The flaw is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow). It was assigned by VulDB as the CNA and published on 2026-09-14.
Why It Matters
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The attack is network-reachable with low complexity, requires only low privileges, and needs no user interaction. Confidentiality, integrity, and availability impacts are all rated HIGH, and the scope is CHANGED, meaning a successful attack can affect components beyond the vulnerable one.
A secondary CVSS 4.0 assessment scores it 9.4 (CRITICAL), with high impact to both the vulnerable system and downstream subsequent systems. The CVSS 2.0 score is 9.0.
Because the affected component handles WAN configuration, the vulnerability sits on the boundary between an internal network and the internet; a position where memory corruption would likely be especially consequential for any network sitting behind the device.
What's Vulnerable
- Vendor: D-Link
- Product: DIR-878 (hardware;
cpe:2.3:h:d-link:dir-878:*:*:*:*:*:*:*:*) - Affected version: 120B05
- Affected module: WAN Settings, function
SetWan3Settings
No other products or firmware versions are listed as affected in the supplied NVD record.
Patch Status
The NVD record lists vulnStatus: Received as of 2026-09-14 and does not reference a vendor patch, fixed firmware build, or mitigation advisory. No CISA KEV entry was supplied for this CVE, so no KEV-mandated remediation deadline applies. That absence is not evidence that the vulnerability is unexploited; it indicates only that exploitation has not been confirmed in the records reviewed here. The only vendor reference provided is D-Link's main website; operators should monitor it for a firmware release addressing 120B05.
Sources
- NVD, CVE-2026-90693: https://nvd.nist.gov/vuln/detail/CVE-2026-90693
- VulDB, CVE-2026-90693: https://vuldb.com/cve/CVE-2026-90693
- VulDB, Vulnerability 403226: https://vuldb.com/vuln/403226
- VulDB, CTI Data: https://vuldb.com/vuln/403226/cti
- VulDB, Submission 915573: https://vuldb.com/submit/915573
- Researcher advisory (Amalll-Sec): https://github.com/Amalll-Sec/router-vulnerability-research/blob/main/advisories/d-link/dir-878/SetWan3Settings/README.md
- D-Link: https://www.dlink.com/
One flag outside the deliverable: the hedging note arrived truncated mid-word ("...no confirmed evidence of act"), so its direction was ambiguous, it could have meant add hedging or remove it. I read it as correcting an overclaim, since the original inferred "no confirmed evidence of active exploitation" from the mere absence of a KEV entry in the supplied data, which doesn't follow. If you meant the opposite, state flatly that there's no active exploitation; send the full note and I'll redo that sentence.