Buffer Overflow in D-Link DCS-1100 and DCS-1130 Devices
CVE-2017-8416

8.8HIGH

Key Information:

Vendor
D-Link
Vendor
CVE Published:
2 July 2019

Summary

A vulnerability exists in D-Link DCS-1100 and DCS-1130 devices due to an unbounded buffer copy operation in a custom daemon listening on UDP port 5978. This daemon processes broadcast packets which can be sent by any device, allowing an attacker to execute arbitrary commands on the vulnerable device. By exploiting this flaw, attackers can manipulate the stack pointer and take control of the device by sending a specially crafted UDP packet, enabling unauthorized command execution without proper authentication.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.