Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-90693: D-Link DIR-878 router allows remote takeover

CVE-2026-90693 · published 26 days ago
Summary

The DIR‑878 router's WAN settings code can be tricked by a crafted network request, causing it to overflow its memory. This lets an attacker gain control of the device from outside the network. Update the router firmware to the latest version or apply the vendor’s recommended patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-878 120B05
Original advisory text
A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffe...
A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the attack is possible.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Sources
CVE-2026-90693 · MITRE
Track software like this
Free during beta