Stack-Based Buffer Overflow in D-Link DIR-868L Authentication Component
CVE-2026-94089
Key Information:
Badges
What is CVE-2026-94089?
A stack-based buffer overflow vulnerability exists in the authentication component of the D-Link DIR-868L firmware version 2.01b05. This security issue arises from improper handling of the 'strcpy' function within the '/webfa_authentication.cgi' file. By manipulating the 'id' or 'password' parameters, an attacker can remotely execute arbitrary code, potentially compromising the device's integrity. The vulnerability is publicly disclosed, making it urgent for users to apply appropriate security measures.
Affected Version(s)
DIR-868L 2.01b05
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved