Stack-based Buffer Overflow in D-Link Devices
CVE-2019-10892
9.8CRITICAL
What is CVE-2019-10892?
An identified vulnerability in D-Link DIR-806 devices allows for a stack-based buffer overflow due to improper handling of user-controlled parameters in the HTTP header. The hnap_main function calls sprintf without verifying the length of strings, potentially enabling attackers to exploit this oversight. This can result in arbitrary code execution, raising concerns for users relying on D-Link's security protocols.