CVE-2019-9125: D-Link Dir-878 Firmware
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.
Affected products
- D-Link Dir-878 Firmware: version 1.12b01 only
Published 2019-02-25. Last modified 2026-06-17.