PT-2023-8306 · D Link · D-Link Dir-X3260

·

CVE-2023-51615

·

Publicado

2023-07-06

·

Atualizado

2024-11-22

CVSS v2.0

7.2

Alta

VetorAV:A/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-X3260 (affected versions not specified)
Description The issue is related to a buffer overflow vulnerability in the prog.cgi component of D-Link DIR-X3260 Wi-Fi routers, allowing remote attackers to execute arbitrary code. The vulnerability exists due to the lack of proper validation of a user-supplied string before copying it to a fixed-length stack-based buffer. This can be exploited by network-adjacent attackers who have authentication credentials. The vulnerability is associated with the SetQuickVPNSettings PSK function and can allow code execution in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00420
CVE-2023-51615
ZDI-24-035

Produtos afetados

D-Link Dir-X3260