CVE-2026-2856: D-Link DWR-M960 Filter Configuration Endpoint formFilter sub_424AFC stack-based overflow
A vulnerability was found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub424AFC of the file /boafrm/formFilter of the component Filter Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2856?
The severity of CVE-2026-2856 is critical due to the potential for stack-based buffer overflow that can lead to remote code execution.
How do I fix CVE-2026-2856?
To fix CVE-2026-2856, update the D-Link DWR-M960 to the latest firmware version provided by D-Link.
What systems are affected by CVE-2026-2856?
CVE-2026-2856 affects the D-Link DWR-M960 model with firmware version 1.01.07.
What kind of attacks can exploit CVE-2026-2856?
CVE-2026-2856 can be exploited through remote attacks utilizing crafted HTTP requests that manipulate the submit-url argument.
Can CVE-2026-2856 lead to data breaches?
Yes, CVE-2026-2856 can potentially lead to data breaches as it allows attackers to execute arbitrary code on the device.