PT-2016-6637 · D Link · Dir-823+9

·

CVE-2016-5681

·

Published

2016-08-25

·

Updated

2026-06-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-850L B1 versions prior to 2.07WWB05 D-Link DIR-817 Ax (affected versions not specified) D-Link DIR-818LW Bx versions prior to 2.05b03beta03 D-Link DIR-822 C1 versions prior to 3.01WWb02 D-Link DIR-823 A1 versions prior to 1.00WWb05 D-Link DIR-895L A1 versions prior to 1.11WWb04 D-Link DIR-890L A1 versions prior to 1.09b14 D-Link DIR-885L A1 versions prior to 1.11WWb07 D-Link DIR-880L A1 versions prior to 1.07WWb08 D-Link DIR-868L B1 versions prior to 2.03WWb01 D-Link DIR-868L C1 versions prior to 3.00WWb01
Description A stack-based buffer overflow occurs in the 'dws/api/Login' endpoint. This issue allows remote attackers to execute arbitrary code by sending a long session cookie. A stack-based buffer overflow is a condition where a program writes more data to a buffer located on the stack than the buffer is allocated to hold, potentially overwriting adjacent memory.
Recommendations Update DIR-850L B1 to version 2.07WWB05 or later. Update DIR-818LW Bx to version 2.05b03beta03 or later. Update DIR-822 C1 to version 3.01WWb02 or later. Update DIR-823 A1 to version 1.00WWb05 or later. Update DIR-895L A1 to version 1.11WWb04 or later. Update DIR-890L A1 to version 1.09b14 or later. Update DIR-885L A1 to version 1.11WWb07 or later. Update DIR-880L A1 to version 1.07WWb08 or later. Update DIR-868L B1 to version 2.03WWb01 or later. Update DIR-868L C1 to version 3.00WWb01 or later. At the moment, there is no information about a newer version that contains a fix for DIR-817 Ax.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-5681

Affected Products

Dir-817
Dir-818Lw
Dir-822
Dir-823
Dir-850L
Dir-868L
Dir-880L
Dir-885L
Dir-890L
Dir-895L