D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow
First seen Sep 15, 2026 · Updated Sep 15, 2026 · CVSS 9.9
A critical stack-based buffer overflow vulnerability has been identified in the D-Link DIR-878 router firmware version 120B05, specifically within the SetWan3Settings function of the WAN Settings component. The flaw is remotely exploitable via malicious input to the Primary/Secondary DNS arguments, potentially allowing an attacker to execute arbitrary code or crash the device without authentication.
Technical Analysis
CVE-2026-90693 stems from insufficient bounds checking in the SetWan3Settings function when processing the Primary/Secondary DNS parameters within WAN configuration requests, leading to a classic stack-based buffer overflow. Given the CVSS score of 9.9, exploitation likely requires no authentication and can be performed remotely over the network, potentially via the router's HNAP or SOAP-based management interface commonly abused in D-Link firmware. Successful exploitation could allow attackers to overwrite the return address on the stack and achieve arbitrary code execution with elevated privileges on the device's embedded OS, enabling full device takeover, traffic interception, or use as a pivot point into internal networks. This class of vulnerability is frequently weaponized by IoT botnets (e.g., Mirai variants) for mass scanning and exploitation once a public PoC is released. Organizations that deploy AI agents or edge inference workloads behind compromised DIR-878 routers face risk of man-in-the-middle traffic manipulation, API key interception, or DNS hijacking that could redirect agent tool-use calls or RAG pipeline requests to attacker-controlled endpoints.
Affected Systems
D-Link DIR-878 router, firmware version 120B05 and potentially earlier/related firmware branches using the same SetWan3Settings implementation
Indicators of Compromise
- No specific IOCs published at this time; monitor for unusual HNAP/SOAP requests to WAN Settings endpoints on DIR-878 devices; watch for anomalous outbound traffic or unexpected reboots from affected routers
Remediation Steps
- 1
Apply Firmware Update
Check D-Link's support site for a patched firmware release addressing CVE-2026-90693 and apply immediately once available.
- 2
Restrict Remote Management
Disable remote/WAN-side administration access to the router and restrict configuration interfaces to trusted LAN-only access.
- 3
Network Segmentation
Isolate IoT and network infrastructure devices, including routers, from segments hosting AI agent infrastructure, RAG pipelines, or credential stores.
- 4
Monitor and Detect
Deploy network intrusion detection rules to flag anomalous WAN Settings API calls or malformed parameters targeting SetWan3Settings.
- 5
Replace End-of-Life Hardware
If no patch is issued, plan replacement of the DIR-878 with actively supported hardware given its critical severity and remote exploitability.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.