Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-90680: D-Link DIR-823G router can be remotely compromised via memory overflow

CVE-2026-90680 · published 27 days ago
Summary

The DIR-823G router's web interface function that sets static routes can be tricked into writing too much data, causing a memory overflow. An attacker from outside the network could exploit this to take control of the router. Update the router firmware to the latest version or apply the vendor's patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-823g 1.0.2B05_20181207
Original advisory text
D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-119Buffer Overflow
CWE-121Stack-based Buffer Overflow
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Sources
CVE-2026-90680 · MITRE
Track software like this
Free during beta