Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-90692: D-Link DIR-878 router can be remotely crashed via IPv6 DNS

CVE-2026-90692 · published 26 days ago
Summary

The Dynamic DNS IPv6 settings on the D-Link DIR-878 router can be manipulated to cause a memory overflow, letting an attacker crash the device from afar. This could disrupt network connectivity and potentially allow further attacks. Install the latest firmware update from D-Link or disable the IPv6 Dynamic DNS feature until a fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-878 120B05
Original advisory text
D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow
A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched remotely.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-119Buffer Overflow
CWE-121Stack-based Buffer Overflow
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Sources
CVE-2026-90692 · MITRE
Track software like this
Free during beta