Overview
D-Link DIR routers contain a stack-based buffer overflow vulnerability, which may allow a remote attack to execute arbitrary code.
Description
CWE-121: Stack-based Buffer Overflow - CVE-2016-5681 A stack-based buffer overflow occurs in the function within the cgibin binary which validates the session cookie.
|
Impact
This function allows a buffer overflow condition in which arbitrary code may be executed. The impact may vary depending on if the use case is local or remote. |
Solution
Apply Updates |
Restrict Access |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| Temporal | 8.4 | E:POC/RL:ND/RC:C |
| Environmental | 6.3 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Daniel Romero @daniel_rome (NCC Group) for reporting this vulnerability.
This document was written by Trent Novelly.
Other Information
| CVE IDs: | CVE-2016-5681 |
| Date Public: | 2016-08-11 |
| Date First Published: | 2016-08-11 |
| Date Last Updated: | 2016-08-12 19:04 UTC |
| Document Revision: | 17 |