CVE-2026-2960: D-Link DWR-M960 formDhcpv6s sub_468D64 stack-based overflow
A flaw has been found in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub468D64 of the file /boafrm/formDhcpv6s. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2960?
CVE-2026-2960 has a critical severity due to the potential for stack-based buffer overflow that can lead to arbitrary code execution.
How do I fix CVE-2026-2960?
To mitigate CVE-2026-2960, update the D-Link DWR-M960 to the latest firmware version released by D-Link.
What versions are affected by CVE-2026-2960?
CVE-2026-2960 affects the D-Link DWR-M960 running firmware version 1.01.07.
What is the impact of exploiting CVE-2026-2960?
Exploiting CVE-2026-2960 can allow an attacker to execute arbitrary code on the device, potentially leading to unauthorized access or control.
How can CVE-2026-2960 be exploited?
An attacker can exploit CVE-2026-2960 by manipulating the argument submit-url in the formDhcpv6s function, leading to a stack-based buffer overflow.