Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-90680: D-Link DIR-823G router can be remotely compromised via memory overflow
CVE-2026-90680 · published 27 days ago
Summary
The DIR-823G router's web interface function that sets static routes can be tricked into writing too much data, causing a memory overflow. An attacker from outside the network could exploit this to take control of the router. Update the router firmware to the latest version or apply the vendor's patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dir-823g | 1.0.2B05_20181207 |
Original advisory text
D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-119Buffer Overflow
CWE-121Stack-based Buffer Overflow
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Track software like this
Free during beta