D-Link DWR-M960 Stack-Based Buffer Overflow Vulnerability in QoS Configuration

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the D-Link DWR-M960 router, specifically in the QoS configuration endpoint '/boafrm/formIpQoS' on firmware version 1.01.07. The vulnerability arises in the function 'sub_427D74', where the 'submit-url' parameter is processed without proper length validation. This oversight allows remote attackers to send oversized 'submit-url' values, leading to memory corruption that could cause a denial-of-service condition or potentially allow arbitrary code execution.

Impact

Exploitation of this vulnerability can cause the web server to crash or the device to reboot unexpectedly. Additionally, by carefully crafting the input, an attacker could overwrite function pointers or other control structures in memory to execute arbitrary code with elevated privileges.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/boafrm/formIpQoS' with the 'save_apply' parameter and an oversized 'submit-url' value. This can be done using a tool like Burp Suite to intercept and modify the request.

Added: Feb 21, 2026, 8:19 PM
Updated: Feb 21, 2026, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.2
remediation
0.0
relevance
3.2
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.