CVE-2026-2881: D-Link DWR-M960 Advanced Firewall Configuration Endpoint formFirewallAdv sub_425FF8 stack-based overflow
A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub425FF8 of the file /boafrm/formFirewallAdv of the component Advanced Firewall Configuration Endpoint. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2881?
CVE-2026-2881 is considered to be of high severity due to its potential for stack-based overflow exploitation.
How do I fix CVE-2026-2881?
To fix CVE-2026-2881, upgrade the D-Link DWR-M960 to the latest firmware version provided by D-Link.
What does CVE-2026-2881 affect?
CVE-2026-2881 affects the Advanced Firewall Configuration feature in the D-Link DWR-M960 router.
What type of vulnerability is CVE-2026-2881?
CVE-2026-2881 is a stack-based buffer overflow vulnerability.
Who is affected by CVE-2026-2881?
Users of the D-Link DWR-M960 router running firmware version 1.01.07 are affected by CVE-2026-2881.