CRITICAL🇵🇱 Wersja polska

CVE-2012-10021

CVSS 9.3v4.0pub. 2025-07-31upd. 2025-09-23

A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin. A remote unauthenticated attacker can exploit this to execute arbitrary code with root privileges on the device.

🤖 AI Analysis
How it works

The vulnerability results from unsafe use of the sprintf() function in the getAuthCode() function when processing user-supplied CAPTCHA data. The attacker sends a crafted request to the /goform/formLogin endpoint, passing an excessively long value for the FILECODE parameter. The lack of input length verification causes a stack-based buffer overflow, which allows overwriting the return address and hijacking program execution flow. As a result, the attacker can execute arbitrary code with root privileges on the vulnerable device.

Impact

An attacker can remotely execute arbitrary code (RCE) with root privileges on the device, gaining full control over the router without requiring any authentication credentials.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Due to the age of the device and firmware, verify the availability of updates from the manufacturer (D-Link); if an update is not available, it is recommended to isolate the device from the public internet, restrict access to the administrative panel exclusively to trusted local networks, and consider replacing the device with a model supported by the manufacturer.

Who is affected

D-Link DIR-605L Wireless N300 Cloud Router with firmware version 1.12 and 1.13

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dir 605l

    HW
    Dlink
    all versions
  • Dlink Dir 605l Firmware

    OS
    Dlink
    1.12 – 1.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth BypassMemory
CWE
References

Related vulnerabilities

CVE-2014-8361CRITICAL9.8⚠ KEVPL ✓same product

RCE w usłudze miniigd SOAP Realtek SDK — D-Link DIR-605L/905L

CVE-2026-42373CRITICAL9.8PL ✓same product

Hardcoded backdoor telnet w D-Link DIR-605L B2 — pełny dostęp root

CVE-2023-29961CRITICAL9.8PL ✓same product

Stack overflow w D-Link DIR-605L — podatność przez endpoint formTcpipSetup

CVE-2023-24350CRITICAL9.8PL ✓same product

Stack overflow w routerze D-Link DIR-605L via parametr smtp_email_subject

CVE-2023-24348CRITICAL9.8PL ✓same product

Stack overflow w D-Link DIR-605L via parametr curTime w formSetACLFilter