D-Link DAP-1325 SetAPLanSettings SubnetMask Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-41205
8.8HIGH
Summary
A stack-based buffer overflow vulnerability exists in the D-Link DAP-1325 routers, specifically within the handling of XML data used by the HNAP1 SOAP endpoint. This flaw arises from inadequate validation of user-supplied data length before it is copied into a fixed-length stack buffer. As a result, network-adjacent attackers have the potential to execute arbitrary code on the affected system without the need for authentication. This significant security issue emphasizes the importance of robust input validation in network devices.
Affected Version(s)
DAP-1325 1.07b01
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved