Executive brief
D-Link DIR-895L is a wireless router used to provide internet connectivity in homes and small businesses. A stack-based buffer overflow in the DHCP server component (udhcpcd) can be exploited by an attacker on the local network to crash the device or execute arbitrary code, potentially compromising network security and disrupting service availability.
Technical details
The vulnerability is a stack-based buffer overflow in the sendOffer/sendACK functions within udhcpcd/serverpacket.c of the D-Link DIR-895L A1_102b07 firmware. The flaw is triggered during the parsing of DHCP Option 125 (TR-111) in DHCP server responses. An attacker on the local network can craft a malicious DHCP packet to overflow the stack buffer, potentially enabling code execution or denial of service. The attack requires network access to the DHCP server and does not require authentication. Public exploits have been released.
Affected products
- D-Link DIR-895L A1_102b07
Timeline
- 2026-09-08: disclosed
- other: Public exploit available