Buffer Overflow in D-Link DSL-3788 Increases Risk for Users
CVE-2024-57440

7.5HIGH

Key Information:

Vendor
D-Link
Status
Vendor
CVE Published:
20 March 2025

Summary

The D-Link DSL-3788 revA1 1.01R1B036_EU_EN has a critical buffer overflow vulnerability in the COMM_MAKECustomMsg function within the webproc CGI component. This flaw can be exploited to execute arbitrary code, potentially allowing an attacker to gain unauthorized control over the device. Users are urged to apply available patches and review security practices to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.