SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90692

CRITICAL · CVSS 9.9 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

D-Link DIR-878 devices are vulnerable to a stack-based buffer overflow in the Dynamic DNS IPv6 Settings function, which can be exploited remotely through manipulated IPv6 address or hostname inputs. This critical vulnerability, with a CVSS score of 9.9, could allow attackers to execute arbitrary code, potentially compromising the device and the network it is connected to. Organizations using affected D-Link routers should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90692
Severity
CRITICAL
CVSS
9.9
EPSS
0.47%

Original NVD Description

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched remotely.