Overview
D-Link DIR routers contain a stack-based buffer overflow vulnerability, which may allow a remote attack to execute arbitrary code.
Description
CWE-121: Stack-based Buffer Overflow - CVE-2016-5681 A stack-based buffer overflow occurs in the function within the cgibin binary which validates the session cookie.
|
Impact
This function allows a buffer overflow condition in which arbitrary code may be executed. The impact may vary depending on if the use case is local or remote. |
Solution
Apply Updates |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 8.4 | E:POC/RL:ND/RC:C |
Environmental | 6.3 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Daniel Romero @daniel_rome (NCC Group) for reporting this vulnerability.
This document was written by Trent Novelly.
Other Information
CVE IDs: | CVE-2016-5681 |
Date Public: | 2016-08-11 |
Date First Published: | 2016-08-11 |
Date Last Updated: | 2016-08-12 19:04 UTC |
Document Revision: | 17 |