criticalOther

D-Link DIR-878 SetDynamicDNSIPv6Settings Stack-Based Buffer Overflow

First seen Sep 15, 2026 · Updated Sep 15, 2026 · CVSS 9.9

d-linkrouterbuffer-overflowrceiotnetwork-deviceunauthenticated

A critical stack-based buffer overflow vulnerability exists in D-Link DIR-878 routers running firmware 120B05, affecting the SetDynamicDNSIPv6Settings function within the Dynamic DNS IPv6 Settings component. The flaw can be triggered remotely via malicious input in the IPv6Address/Hostname parameter, potentially allowing full device compromise without authentication.

Technical Analysis

The vulnerability resides in the SetDynamicDNSIPv6Settings function, where improper bounds checking on the IPv6Address/Hostname argument allows an attacker to overflow a stack-based buffer, likely leading to arbitrary code execution or denial of service. Given the CVSS score of 9.9, the attack vector is remote and requires minimal privileges, making it highly exploitable over the network without user interaction. Exploitation could allow attackers to fully compromise the router firmware, pivot into internal networks, intercept traffic, or deploy persistent implants such as botnet malware. Organizations that deploy AI agent infrastructure behind compromised DIR-878 devices could face man-in-the-middle interception of API keys, credentials, or model traffic, or have agent network access redirected through attacker-controlled DNS, making this agent-relevant for any environment where these routers sit on the network path to agent or RAG pipeline endpoints.

Affected Systems

D-Link DIR-878 routers running firmware version 120B05, specifically the Dynamic DNS IPv6 Settings configuration interface.

Indicators of Compromise

  • No specific IOCs published at this time; monitor for anomalous SetDynamicDNSIPv6Settings API calls with oversized IPv6Address/Hostname parameters

Remediation Steps

  1. 1

    Apply Firmware Update

    Check D-Link's support portal for a patched firmware release addressing this vulnerability and apply it immediately.

  2. 2

    Disable Remote Management

    Disable remote/WAN-side administrative access to the router to reduce the remote attack surface.

  3. 3

    Network Segmentation

    Isolate IoT and network infrastructure devices, including routers, from critical systems such as AI agent hosts and RAG pipeline servers.

  4. 4

    Replace End-of-Life Hardware

    If no patch is available and the device is end-of-life, replace it with actively supported networking hardware.

  5. 5

    Monitor Network Traffic

    Deploy IDS/IPS rules to detect abnormal Dynamic DNS configuration requests or oversized parameter payloads targeting the device's management interface.

CVE / Advisory IDs

CVE-2026-90692

Industries Most Exposed

Consumer/Home NetworkingSmall BusinessTelecommunicationsManaged Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.