CVE-2026-90680: D-Link Dir-823g

Critical severity, CVSS 9.9. EPSS: 0.9% chance of exploitation in the next 30 days.

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.

Affected products

  • D-Link Dir-823g: version 1.0.2B05_20181207 only

Published 2026-09-14. Last modified 2026-09-16.