Disclosure
**CVE-2026-2854** is a high-severity security flaw affecting the D-Link DWR-M960 router, specifically version 1.01.07. The vulnerability resides within the `sub_4611CC` function of the `/boafrm/formNtp` component, which handles NTP (Network Time Protocol) configuration. An attacker can manipulate the `submit-url` argument in the NTP configuration endpoint, leading to a **stack-based buffer overflow**. This flaw allows remote attackers to execute arbitrary code or cause denial-of-service conditions without requiring user interaction or privileges.
#Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #BufferOverflow https://cvetodo.com/cve/CVE-2026-2854
Post summary
CVE‑2026‑2854 is a stack‑based buffer overflow in the D-Link DWR‑M960 router’s NTP configuration, enabling remote code execution or DoS; no PoC, exploit code, patch, or active exploitation is reported.