Stack-based Buffer Overflow in D-Link DSL-2640B Devices
CVE-2020-9276
8.8HIGH
Summary
A vulnerability was found in D-Link DSL-2640B B2 EU_4.01B devices, specifically in the function do_cgi() which handles CGI requests on the device's web server. This flaw can be exploited remotely by an attacker, allowing for unauthorized access that can result in a stack-based buffer overflow. Combining this vulnerability with another identified issue (CVE-2020-9277) can further facilitate the exploitation process, posing significant risks to network security.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved