D-Link DIR-3040 prog.cgi SetUsersSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-41228
6.8MEDIUM
Summary
A stack-based buffer overflow vulnerability exists in the prog.cgi binary of D-Link DIR-3040 routers, impacting their web server functionality. This flaw allows network-adjacent attackers to execute arbitrary code on affected systems once they have authenticated. The vulnerability arises from insufficient validation of a user-supplied string, which can lead to the overwriting of the stack, potentially granting elevated privileges to an attacker. Security measures and updates are crucial to mitigate any risks associated with this vulnerability.
Affected Version(s)
DIR-3040 120B03
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved