CVE-2026-2855Disclosure(dlink / dwr-m960)

LOWCVSS 7.4 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Handler. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dwr-m960
  • dwr-m960_firmware

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
dwr-m960dwr-m960_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-20: 4Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2855 A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Handler. The … https://www.cve.org/CVERecord?id=CVE-2026-2855

    Post summary

    CVE-2026-2855 has been disclosed as affecting the DDNS Settings Handler of the D-Link DWR-M960, but no exploit or mitigation details are provided.

    0000088
    56.4K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2855: HIGH] Vulnerability in D-Link DWR-M960 1.01.07 could lead to a remote stack-based buffer overflow attack through manipulation of submit-url argument in DDNS Settings Handler.#cve,CVE-2026-2855,#cybersecurity https://cvefind.com/CVE-2026-2855

    Post summary

    The post announces CVE-2026-2855, detailing a remote stack-based buffer overflow in the DDNS Settings Handler of D-Link DWR-M960 1.01.07, but does not mention PoC, exploit, or patch.

    0000034
    578 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-2855 is a high-severity vulnerability affecting the D-Link DWR-M960 router firmware version 1.01.07. The core issue resides within the `sub_4648F0` function located in `/boafrm/formDdns`, part of the DDNS (Dynamic DNS) Settings Handler. The vulnerability allows an attacker to manipulate the `submit-url` argument, leading to a stack-based buffer overflow. This flaw can be exploited remotely without user interaction, potentially allowing an attacker to execute arbitrary code or cause a denial of service. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS #BufferOverflow https://cvetodo.com/cve/CVE-2026-2855

    Post summary

    CVE-2026-2855 is a high‑severity stack‑based buffer overflow in D‑Link routers, enabling remote code execution; the post provides technical details but no PoC, exploit, or patch information.

    0000025
    20 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting D-Link DWR-M960 (CVE-2026-2855) https://vuldb.com/?id.347094

    Post summary

    The post announces an increased severity for CVE‑2026‑2855 on a D‑Link router but provides no further technical detail, exploit code, patch information, or evidence of active exploitation.

    0000051
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdwr-m960b1--
OSdlinkdwr-m960_firmware1.01.07--

Explore more