Stack-based Buffer Overflow in D-Link DIR-100 Routers
CVE-2013-6027

Currently unrated

Key Information:

Vendor

D-Link

Status
Vendor
CVE Published:
19 October 2013

What is CVE-2013-6027?

The D-Link DIR-100 router is susceptible to a stack-based buffer overflow in the RuntimeDiagnosticPing function, which is located in the /bin/webs executable. This vulnerability may allow authenticated remote administrators to execute arbitrary commands. Specifically, by sending a specially crafted long set/runtime/diagnostic/pingIp parameter to the Tools/tools_misc.xgi endpoint, an attacker can manipulate the execution flow of the router's firmware, potentially leading to unauthorized access and control. Timely patching and network monitoring are crucial to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2013-6027 : Stack-based Buffer Overflow in D-Link DIR-100 Routers