CVE-2026-2926Disclosure(dlink / dwr-m960)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch dlink dwr-m960 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4237AC of the file /boafrm/formLteSetup of the component LTE Configuration Endpoint. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dwr-m960
  • dwr-m960_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dwr-m960dwr-m960_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-22: 2Mentions · 2026-02-27: 1PoC Mentioned / Linked · 2026-02-22: 1Patch / Workaround · 2026-02-22: 1Technical Details · 2026-02-22: 2Technical Details · 2026-02-27: 102-2202-27
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-222
Disclosure1PoC1
2026-02-271
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2926 (CVSS:7.4, HIGH) is Analyzed. A flaw has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4237AC of the file /boafrm/formLteSetup ..https://nvd.nist.gov/vuln/detail/CVE-2026-2926 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-2926 is a high‑severity flaw in D‑Link DWR‑M960 firmware affecting the sub_4237AC function; no PoC, exploit, or patch information is provided.

    0000021
    173 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2926 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2926 #CVE-2026-2926 #CVE #High #CyberSecurity #InfoSec https://t.co/0J2AMqnR4C

    Post summary

    A new high‑severity CVE-2026-2926 has been announced with a CVSS score of 8.8, affecting multiple unspecified products, but no PoC, exploit, or patch details are provided.

    0000045
    57 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    PoC

    🚨 HIGH-severity CVE-2026-2926: D-Link DWR-M960 routers (v1.01.07) face a remote, unauthenticated buffer overflow risk — public PoC out! Isolate devices & monitor for attacks. Patch when available. Details: https://radar.offseq.com/threat/cve-2026-2926-stack-based-buffer-overfl... https://t.co/CZdZaXCli7

    Post summary

    A high‑severity buffer overflow vulnerability (CVE‑2026‑2926) in D‑Link DWR‑M960 routers has a publicly available PoC; users should isolate devices and apply patches when released.

    0000057
    269 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdwr-m960b1--
OSdlinkdwr-m960_firmware1.01.07--

Explore more