D-Link DAP-1325 SetAPLanSettings PrimaryDNS Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-41203
8.8HIGH
Summary
The vulnerability identified in D-Link DAP-1325 routers involves a stack-based buffer overflow that occurs due to inadequate validation of XML data length supplied to the HNAP1 SOAP endpoint. Attackers with network access can exploit this flaw to execute arbitrary code on the device without requiring authentication, enabling them to gain root level access. The lack of stringent checks on user input poses significant risks for users of this router model.
Affected Version(s)
DAP-1325 1.07b01
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved