Integer Signedness Error in D-Link AirPlus DI-614+ Due to DHCP Vulnerability
CVE-2004-0661

Currently unrated

Key Information:

Vendor

D-link

Vendor
CVE Published:
6 August 2004

What is CVE-2004-0661?

An integer signedness error in the D-Link AirPlus DI-614+ router, specifically in firmware versions 2.30 and earlier, allows remote attackers to exploit the DHCP service. By sending a crafted DHCP request with the LEASETIME option set to -1, an attacker can cause the device to enter a denial-of-service state due to IP lease depletion. This bug could enable an attacker to exhaust the DHCP leases, rendering network accessibility impossible for legitimate users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.