D-Link DIR-878 SetDynamicDNSIPv6Settings Stack-Based Buffer Overflow
First seen Sep 15, 2026 · Updated Sep 15, 2026 · CVSS 9.9
A critical stack-based buffer overflow vulnerability exists in D-Link DIR-878 routers running firmware 120B05, affecting the SetDynamicDNSIPv6Settings function within the Dynamic DNS IPv6 Settings component. The flaw can be triggered remotely via malicious input in the IPv6Address/Hostname parameter, potentially allowing full device compromise without authentication.
Technical Analysis
The vulnerability resides in the SetDynamicDNSIPv6Settings function, where improper bounds checking on the IPv6Address/Hostname argument allows an attacker to overflow a stack-based buffer, likely leading to arbitrary code execution or denial of service. Given the CVSS score of 9.9, the attack vector is remote and requires minimal privileges, making it highly exploitable over the network without user interaction. Exploitation could allow attackers to fully compromise the router firmware, pivot into internal networks, intercept traffic, or deploy persistent implants such as botnet malware. Organizations that deploy AI agent infrastructure behind compromised DIR-878 devices could face man-in-the-middle interception of API keys, credentials, or model traffic, or have agent network access redirected through attacker-controlled DNS, making this agent-relevant for any environment where these routers sit on the network path to agent or RAG pipeline endpoints.
Affected Systems
D-Link DIR-878 routers running firmware version 120B05, specifically the Dynamic DNS IPv6 Settings configuration interface.
Indicators of Compromise
- No specific IOCs published at this time; monitor for anomalous SetDynamicDNSIPv6Settings API calls with oversized IPv6Address/Hostname parameters
Remediation Steps
- 1
Apply Firmware Update
Check D-Link's support portal for a patched firmware release addressing this vulnerability and apply it immediately.
- 2
Disable Remote Management
Disable remote/WAN-side administrative access to the router to reduce the remote attack surface.
- 3
Network Segmentation
Isolate IoT and network infrastructure devices, including routers, from critical systems such as AI agent hosts and RAG pipeline servers.
- 4
Replace End-of-Life Hardware
If no patch is available and the device is end-of-life, replace it with actively supported networking hardware.
- 5
Monitor Network Traffic
Deploy IDS/IPS rules to detect abnormal Dynamic DNS configuration requests or oversized parameter payloads targeting the device's management interface.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.