Junglewise Threat Intelligence

CVE-2026-90693: D-Link DIR-878 stack buffer overflow in WAN settings

CVE-2026-90693 · Severity: critical · CVSS 9.9 · Published 2026-09-14

Vendors: D-Link.

Executive brief

D-Link DIR-878 is a wireless router used in homes and small offices to manage network connectivity. A vulnerability in its web management interface allows an attacker to crash the router or potentially execute malicious code by sending oversized DNS configuration values to the WAN settings function, disrupting network service and potentially compromising the device.

Technical details

The vulnerability is a classic stack-based buffer overflow in the SetWan3Settings web handler. The affected component copies DNS Primary and Secondary values into 72-byte stack buffers using unbounded sprintf and strcat operations without input length validation. An attacker with network access to the router's web interface can supply oversized values that overflow the stack, causing memory corruption and crashing the web management process (denial of service), and potentially enabling remote code execution. No patch status is explicitly mentioned in the advisory.

Affected products

  • D-Link DIR-878 120B05

Timeline

  • 2026-09-14: disclosed
  • other: Not yet exploited in the wild at time of disclosure

References