Stack-based Buffer Overflow in D-Link DIR-823G Router
CVE-2026-90680

9.4CRITICAL

Key Information:

Vendor

D-link

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90680?

A security flaw exists in the D-Link DIR-823G with version 1.0.2B05_20181207, affecting the HNAP1 component. The vulnerability arises from improper handling within the strcpy function located in /HNAP1/SetStaticRouteSettings. Attackers can exploit this flaw by manipulating the parameters for PAddress, SubnetMask, or Gateway, leading to a stack-based buffer overflow. This vulnerability is particularly concerning as it can be exploited remotely, potentially compromising the router's functionality and security.

Affected Version(s)

DIR-823G 1.0.2B05_20181207

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AmaIIl (VulDB User)
.