CVE-2026-2854Disclosure(dlink / dwr-m960)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dwr-m960
  • dwr-m960_firmware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
dwr-m960dwr-m960_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-20: 3Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2854 A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint. Executin… https://www.cve.org/CVERecord?id=CVE-2026-2854

    Post summary

    A flaw has been identified in D‑Link DWR‑M960 affecting the NTP configuration endpoint, but the text offers no further details on exploitation, patches, or mitigations.

    0000097
    56.4K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-2854** is a high-severity security flaw affecting the D-Link DWR-M960 router, specifically version 1.01.07. The vulnerability resides within the `sub_4611CC` function of the `/boafrm/formNtp` component, which handles NTP (Network Time Protocol) configuration. An attacker can manipulate the `submit-url` argument in the NTP configuration endpoint, leading to a **stack-based buffer overflow**. This flaw allows remote attackers to execute arbitrary code or cause denial-of-service conditions without requiring user interaction or privileges. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #BufferOverflow https://cvetodo.com/cve/CVE-2026-2854

    Post summary

    CVE‑2026‑2854 is a stack‑based buffer overflow in the D-Link DWR‑M960 router’s NTP configuration, enabling remote code execution or DoS; no PoC, exploit code, patch, or active exploitation is reported.

    0000026
    20 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2854: HIGH] Critical flaw in D-Link DWR-M960 1.01.07 discovered in NTP Configuration Endpoint component. Vulnerability allows remote attackers to execute code via stack-based buffer overflow.#cve,CVE-2026-2854,#cybersecurity https://cvefind.com/CVE-2026-2854

    Post summary

    High‑severity stack‑based buffer overflow discovered on the D-Link DWR‑M960 router, permitting remote attackers to execute code.

    0000037
    578 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdwr-m960b1--
OSdlinkdwr-m960_firmware1.01.07--

Explore more