CVE-2026-2853: D-Link DWR-M960 System Log Configuration Endpoint formSysLog sub_462E14 stack-based overflow
A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub462E14 of the file /boafrm/formSysLog of the component System Log Configuration Endpoint. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2853?
CVE-2026-2853 is rated as high severity due to its potential for exploitation via stack-based buffer overflow.
How do I fix CVE-2026-2853?
To fix CVE-2026-2853, update the firmware for the D-Link DWR-M960 to the latest version released by D-Link.
What component is affected by CVE-2026-2853?
CVE-2026-2853 affects the System Log Configuration Endpoint of the D-Link DWR-M960 router.
Can CVE-2026-2853 be exploited remotely?
Yes, CVE-2026-2853 can be exploited remotely by manipulating the submit-url argument.
What is the primary vulnerability type for CVE-2026-2853?
The primary vulnerability type for CVE-2026-2853 is a stack-based buffer overflow.