Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-60674


A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack overflow. An attacker with physical access or control over a USB device can exploit this vulnerability to potentially execute arbitrary code on the device.


Published

2025-11-13T19:15:48.290

Last Modified

2025-11-17T19:04:24.980

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-121

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-878_firmware 1.01b04 Yes
Hardware dlink dir-878 a1 No

References