Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-90693 2026-09-14

CVE-2026-90693: Critical Stack Overflow in D-Link DIR-878 WAN Settings

"A critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-878 router's WAN Settings handler could allow remote, low-privilege attackers to corrupt memory and potentially compromise the device."

A critical (CVSS 9.9) stack-based buffer overflow in the D-Link DIR-878 router's WAN Settings handler could allow remote, low-privilege attackers to corrupt memory and potentially compromise the device.

What Is It

CVE-2026-90693 is a stack-based buffer overflow in the SetWan3Settings function of the WAN Settings component on D-Link DIR-878 firmware 120B05. According to the published record, manipulation of the Primary/Secondary argument triggers the overflow, and remote exploitation is reported to be possible.

The flaw is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow). It was assigned by VulDB as the CNA and published on 2026-09-14.

Why It Matters

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The attack is network-reachable with low complexity, requires only low privileges, and needs no user interaction. Confidentiality, integrity, and availability impacts are all rated HIGH, and the scope is CHANGED, meaning a successful attack can affect components beyond the vulnerable one.

A secondary CVSS 4.0 assessment scores it 9.4 (CRITICAL), with high impact to both the vulnerable system and downstream subsequent systems. The CVSS 2.0 score is 9.0.

Because the affected component handles WAN configuration, the vulnerability sits on the boundary between an internal network and the internet; a position where memory corruption would likely be especially consequential for any network sitting behind the device.

What's Vulnerable

No other products or firmware versions are listed as affected in the supplied NVD record.

Patch Status

The NVD record lists vulnStatus: Received as of 2026-09-14 and does not reference a vendor patch, fixed firmware build, or mitigation advisory. No CISA KEV entry was supplied for this CVE, so no KEV-mandated remediation deadline applies. That absence is not evidence that the vulnerability is unexploited; it indicates only that exploitation has not been confirmed in the records reviewed here. The only vendor reference provided is D-Link's main website; operators should monitor it for a firmware release addressing 120B05.

Sources


One flag outside the deliverable: the hedging note arrived truncated mid-word ("...no confirmed evidence of act"), so its direction was ambiguous, it could have meant add hedging or remove it. I read it as correcting an overclaim, since the original inferred "no confirmed evidence of active exploitation" from the mere absence of a KEV entry in the supplied data, which doesn't follow. If you meant the opposite, state flatly that there's no active exploitation; send the full note and I'll redo that sentence.