D-Link DI-8003 upgrade_filter.asp upgrade_filter_asp stack-based overflow
Published Nov 10, 2024
8.7
HIGHCVSS 4.0
EPSS 1.21%
Description
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 16.07.16A1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| D-Link | n/a | n/a |
|
- 16.07.16a1
-
- Version 16.07.16a1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| D-Link | DI-8003 Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://github.com/theRaz0r/iot-mycve/blob/main/Dlink_DI8003_stackoverflow/Dlink_DI8003_stackoverflow.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.283633 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.283633 vdb-entrytechnical-descriptionPermissions Required
- https://vuldb.com/?submit.434931 third-party-advisoryThird Party Advisory
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://github.com/theRaz0r/iot-mycve/blob/main/Dlink_DI8003_stackoverflow/Dlink_DI8003_stackoverflow.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.283633 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.283633 | vdb-entrytechnical-descriptionPermissions Required | |
| https://vuldb.com/?submit.434931 | third-party-advisoryThird Party Advisory | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.