CVE-2026-90680

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.

  • Published Sep 14, 2026
  • CVSS 9.4 critical
  • 0.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90680 at the National Vulnerability Database