Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-44405
8.8HIGH
Summary
A stack-based buffer overflow vulnerability exists in the D-Link DAP-1325 routers, specifically within the handling of XML data sent to the HNAP1 SOAP endpoint. This flaw arises from inadequate validation of user-supplied data length before it is copied into a fixed-length buffer. Network-adjacent attackers can exploit this vulnerability to execute arbitrary code under the root context without requiring any authentication, posing significant risks to network integrity and user data security. Proper measures should be taken to mitigate this vulnerability as detailed in advisory ZDI-23-1503.
Affected Version(s)
DAP-1325 1.07b01
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved