D-Link DWR-M960 Stack-Based Buffer Overflow Vulnerability in Operation Mode Configuration Endpoint

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the D-Link DWR-M960 router, specifically in the Operation Mode configuration endpoint (/boafrm/formOpMode) on firmware version 1.01.07. The vulnerability arises in the function sub_462590, where the 'submit-url' parameter is processed. The function lacks proper input validation, allowing remote attackers to exploit this flaw by sending oversized 'submit-url' values, leading to memory corruption.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition, where the device becomes unresponsive or crashes. Additionally, it could allow for arbitrary code execution by overwriting critical memory areas, such as function pointers, and hijacking the execution flow to run malicious code with elevated privileges.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/boafrm/formOpMode' endpoint. The request must include a valid 'mode' parameter to pass the initial validation check, along with an oversized 'submit-url' parameter. This can be done using a tool like Burp Suite to intercept and modify the request.

Added: Feb 22, 2026, 5:19 AM
Updated: Feb 22, 2026, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.2
remediation
0.0
relevance
3.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.