A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin. A remote unauthenticated attacker can exploit this to execute arbitrary code with root privileges on the device.
The vulnerability results from unsafe use of the sprintf() function in the getAuthCode() function when processing user-supplied CAPTCHA data. The attacker sends a crafted request to the /goform/formLogin endpoint, passing an excessively long value for the FILECODE parameter. The lack of input length verification causes a stack-based buffer overflow, which allows overwriting the return address and hijacking program execution flow. As a result, the attacker can execute arbitrary code with root privileges on the vulnerable device.
An attacker can remotely execute arbitrary code (RCE) with root privileges on the device, gaining full control over the router without requiring any authentication credentials.
Apply patches available from the manufacturer according to the references. Due to the age of the device and firmware, verify the availability of updates from the manufacturer (D-Link); if an update is not available, it is recommended to isolate the device from the public internet, restrict access to the administrative panel exclusively to trusted local networks, and consider replacing the device with a model supported by the manufacturer.
D-Link DIR-605L Wireless N300 Cloud Router with firmware version 1.12 and 1.13
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dir 605l
HWDlinkall versionsDlink Dir 605l Firmware
OSDlink1.12 – 1.13
Related vulnerabilities
RCE w usłudze miniigd SOAP Realtek SDK — D-Link DIR-605L/905L
Hardcoded backdoor telnet w D-Link DIR-605L B2 — pełny dostęp root
Stack overflow w D-Link DIR-605L — podatność przez endpoint formTcpipSetup
Stack overflow w routerze D-Link DIR-605L via parametr smtp_email_subject
Stack overflow w D-Link DIR-605L via parametr curTime w formSetACLFilter