Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-44405

8.8HIGH

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
3 May 2024

Summary

A stack-based buffer overflow vulnerability exists in the D-Link DAP-1325 routers, specifically within the handling of XML data sent to the HNAP1 SOAP endpoint. This flaw arises from inadequate validation of user-supplied data length before it is copied into a fixed-length buffer. Network-adjacent attackers can exploit this vulnerability to execute arbitrary code under the root context without requiring any authentication, posing significant risks to network integrity and user data security. Proper measures should be taken to mitigate this vulnerability as detailed in advisory ZDI-23-1503.

Affected Version(s)

DAP-1325 1.07b01

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.