📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 9h Global supply_chain Software Development and Technology HIGH 14h Global apt Government/Critical Infrastructure CRITICAL 16h Global vulnerability Enterprise Software / Data Analytics CRITICAL 17h Global vulnerability Artificial Intelligence and Technology HIGH 20h Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 9h Global supply_chain Software Development and Technology HIGH 14h Global apt Government/Critical Infrastructure CRITICAL 16h Global vulnerability Enterprise Software / Data Analytics CRITICAL 17h Global vulnerability Artificial Intelligence and Technology HIGH 20h Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 9h Global supply_chain Software Development and Technology HIGH 14h Global apt Government/Critical Infrastructure CRITICAL 16h Global vulnerability Enterprise Software / Data Analytics CRITICAL 17h Global vulnerability Artificial Intelligence and Technology HIGH 20h Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-2884

High ⚡ Exploit Available
A vulnerability was identified in D-Link DWR-M960 1.01.07. The affected element is the function sub_41914C of the file /boafrm/formWanConfigSetup of the component WAN Interface Setting Handler. The ma
CWE-119 — Weakness Type
Published: Feb 21, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

A vulnerability was identified in D-Link DWR-M960 1.01.07. The affected element is the function sub_41914C of the file /boafrm/formWanConfigSetup of the component WAN Interface Setting Handler. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

🤖 AI Executive Summary

A critical stack-based buffer overflow vulnerability exists in D-Link DWR-M960 router firmware version 1.01.07, affecting the WAN Interface Setting Handler. The vulnerability can be exploited remotely through the submit-url parameter, allowing unauthenticated attackers to execute arbitrary code. With publicly available exploits and widespread router deployment in Saudi networks, immediate patching is essential.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 22:59
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi telecommunications infrastructure (STC, Mobily, Zain), government networks, and enterprise connectivity. D-Link DWR-M960 routers are commonly deployed as edge devices in banking networks (SAMA-regulated institutions), healthcare facilities, and critical infrastructure. Remote code execution capability enables attackers to establish persistent backdoors, intercept encrypted traffic, and pivot into internal networks. Government entities and financial institutions are particularly vulnerable due to reliance on these devices for WAN connectivity.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Banking and Financial Services (SAMA-regulated) Government and Public Administration Healthcare Energy and Utilities Critical Infrastructure Enterprise Networks
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all D-Link DWR-M960 devices running firmware 1.01.07 in your network using network scanning tools
2. Isolate affected devices from critical network segments if patching cannot be completed immediately
3. Implement network-level access controls restricting WAN configuration interface access to authorized administrators only
4. Enable logging on affected devices to detect exploitation attempts

PATCHING GUIDANCE:
1. Download latest firmware from D-Link support portal (verify version > 1.01.07)
2. Backup current configuration before firmware update
3. Apply firmware update through device management interface or serial console
4. Verify successful update by checking firmware version post-reboot
5. Test WAN connectivity and all critical services after update

COMPENSATING CONTROLS (if immediate patching not possible):
1. Restrict access to /boafrm/formWanConfigSetup endpoint using firewall rules
2. Implement Web Application Firewall (WAF) rules to block requests with suspicious submit-url parameters
3. Monitor for exploitation patterns: POST requests to /boafrm/formWanConfigSetup with oversized submit-url values
4. Disable remote management features if not required
5. Implement network segmentation isolating router management interfaces

DETECTION RULES:
1. Monitor for HTTP POST requests to /boafrm/formWanConfigSetup with submit-url parameter length > 256 bytes
2. Alert on unexpected process execution from router web service processes
3. Monitor for unusual outbound connections from affected router devices
4. Track failed and successful authentication attempts to router management interface
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة D-Link DWR-M960 التي تعمل بالإصدار 1.01.07 في شبكتك باستخدام أدوات المسح
2. عزل الأجهزة المتأثرة عن قطاعات الشبكة الحرجة إذا لم يكن التصحيح ممكنًا فورًا
3. تنفيذ عناصر تحكم الوصول على مستوى الشبكة لتقييد الوصول إلى واجهة إعدادات WAN للمسؤولين المصرح لهم فقط
4. تفعيل السجلات على الأجهزة المتأثرة للكشف عن محاولات الاستغلال

إرشادات التصحيح:
1. تحميل أحدث برنامج تثبيت من بوابة دعم D-Link (التحقق من الإصدار > 1.01.07)
2. نسخ احتياطي للإعدادات الحالية قبل تحديث البرنامج
3. تطبيق تحديث البرنامج من خلال واجهة إدارة الجهاز أو وحدة التحكم التسلسلية
4. التحقق من نجاح التحديث بفحص إصدار البرنامج بعد إعادة التشغيل
5. اختبار اتصال WAN وجميع الخدمات الحرجة بعد التحديث

عناصر التحكم البديلة (إذا لم يكن التصحيح الفوري ممكنًا):
1. تقييد الوصول إلى نقطة النهاية /boafrm/formWanConfigSetup باستخدام قواعد جدار الحماية
2. تنفيذ قواعد جدار تطبيقات الويب لحظر الطلبات ذات معاملات submit-url المريبة
3. مراقبة أنماط الاستغلال: طلبات POST إلى /boafrm/formWanConfigSetup بقيم submit-url كبيرة
4. تعطيل ميزات الإدارة البعيدة إذا لم تكن مطلوبة
5. تنفيذ تقسيم الشبكة لعزل واجهات إدارة الموجه

قواعد الكشف:
1. مراقبة طلبات HTTP POST إلى /boafrm/formWanConfigSetup بطول معامل submit-url > 256 بايت
2. تنبيهات عند تنفيذ عمليات غير متوقعة من عمليات خدمة الويب للموجه
3. مراقبة الاتصالات الخارجية غير المعتادة من أجهزة الموجه المتأثرة
4. تتبع محاولات المصادقة الفاشلة والناجحة لواجهة إدارة الموجه
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of network activities ECC 2024 A.13.1.3 - Segregation of networks
🔵 SAMA CSF
SAMA CSF ID.RA-1 - Asset management and vulnerability identification SAMA CSF PR.IP-12 - Security patch management SAMA CSF DE.CM-1 - Detection and monitoring systems SAMA CSF RS.MI-2 - Incident response and containment
🟡 ISO 27001:2022
ISO 27001:2022 A.12.3.1 - Configuration management ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development and change management ISO 27001:2022 A.8.1.1 - Inventory of assets
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patch management PCI DSS 11.2 - Vulnerability scanning PCI DSS 1.1 - Firewall configuration standards
📦 Affected Products / CPE 1 entries
dlink:dwr-m960_firmware:1.01.07
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-119
Exploit ✓ Yes
Patch ✓ Yes
Published 2026-02-21
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-119
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.