Stack Buffer Overflow in D-Link DIR-809 Devices
CVE-2021-33268

9.8CRITICAL

Key Information:

Vendor
D-Link
Vendor
CVE Published:
1 December 2021

Summary

D-Link DIR-809 devices running firmware up to DIR-809Ax_FW1.12WWB03_20190410 are susceptible to a stack buffer overflow vulnerability. This flaw resides in the sub_8003183C function within the /fromLogin handler, which can be exploited by sending a specially crafted POST request to the device. Successful exploitation could potentially lead to unauthorized access or control over affected devices, highlighting the ongoing security challenges in IoT environments.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.