CVE-2026-2928: D-Link DWR-M960 WLAN Encryption Configuration Endpoint formWlEncrypt sub_452CCC stack-based overflow
A vulnerability was found in D-Link DWR-M960 1.01.07. This issue affects the function sub452CCC of the file /boafrm/formWlEncrypt of the component WLAN Encryption Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2928?
CVE-2026-2928 is classified as a high-severity vulnerability due to its potential impact on the D-Link DWR-M960's security.
How do I fix CVE-2026-2928?
To mitigate CVE-2026-2928, update your D-Link DWR-M960 to the latest firmware version provided by the manufacturer.
What type of vulnerability is CVE-2026-2928?
CVE-2026-2928 is a stack-based buffer overflow vulnerability affecting the WLAN Encryption Configuration Endpoint.
What devices are affected by CVE-2026-2928?
CVE-2026-2928 specifically affects the D-Link DWR-M960 device running firmware version 1.01.07.
Can CVE-2026-2928 be exploited remotely?
Yes, CVE-2026-2928 can potentially be exploited remotely without authentication.