CVE-2026-2853Disclosure(dlink / dwr-m960)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch dlink dwr-m960 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Configuration Endpoint. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dwr-m960
  • dwr-m960_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
dwr-m960dwr-m960_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-20: 3PoC Mentioned / Linked · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 302-20
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2853 A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Configuration E… https://www.cve.org/CVERecord?id=CVE-2026-2853

    Post summary

    CVE-2026-2853 was identified in D‑Link DWR‑M960 firmware 1.01.07, impacting the sub_462E14 function within the /boafrm/formSysLog file of the System Log Configuration component.

    0000091
    56.4K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-2853: HIGH] Critical remote stack-based buffer overflow vulnerability discovered in D-Link DWR-M960. Exploit now public. Ensure immediate patching to enhance cybersecurity.#cve,CVE-2026-2853,#cybersecurity https://cvefind.com/CVE-2026-2853

    Post summary

    A critical remote stack‑based buffer overflow in the D‑Link DWR‑M960 has a public exploit; users are urged to patch immediately.

    0000037
    578 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-2853 pertains to a **stack-based buffer overflow** vulnerability found in the D-Link DWR-M960 router, specifically within the function `sub_462E14` of the `/boafrm/formSysLog` component responsible for system log configuration. The flaw is triggered by manipulating the `submit-url` argument, which can lead to arbitrary code execution or system compromise. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation #DDoS https://cvetodo.com/cve/CVE-2026-2853

    Post summary

    A stack‑based buffer overflow in a D‑Link router’s log configuration endpoint enables arbitrary code execution; the post provides technical details but no PoC, exploit code, active exploitation, or patch information.

    0000026
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdwr-m960b1--
OSdlinkdwr-m960_firmware1.01.07--

Explore more