CVE-2026-2962Disclosure(dlink / dwr-m960)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /boafrm/formDateReboot of the component Scheduled Reboot Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dwr-m960
  • dwr-m960_firmware

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-22); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
dwr-m960dwr-m960_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-22: 1Mentions · 2026-02-23: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2202-2302-2702-28
Signal classification1 categories
Disclosure
4100.0%
Referenced assets2 URLs
By indicator
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2962 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /bo..https://nvd.nist.gov/vuln/detail/CVE-2026-2962 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet reports the analysis of CVE‑2026‑2962 against a D‑Link router, giving its CVSS score and affected function, but offers no PoC, exploit details, or patch information.

    0000025
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2962 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /bo..https://nvd.nist.gov/vuln/detail/CVE-2026-2962 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑2962) discovered in the D‑Link DWR‑M960 firmware, providing basic technical details and a link to the NVD entry.

    0000020
    173 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2962 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2962 #CVE-2026-2962 #CVE #High #CyberSecurity #InfoSec https://t.co/dkZE9epmQ2

    Post summary

    A new high‑severity CVE‑2026‑2962 has been announced, affecting multiple unspecified products with a CVSS score of 8.8, but no PoC, exploit, or patch details are provided.

    0000050
    57 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting D-Link DWR-M960 (CVE-2026-2962) https://vuldb.com/?id.347329

    Post summary

    A new vulnerability (CVE-2026-2962) affecting D‑Link DWR‑M960 has been identified with increased severity, but no further technical details or mitigation information are provided.

    0000075
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdwr-m960b1--
OSdlinkdwr-m960_firmware1.01.07--

Explore more