CRITICAL🇵🇱 Wersja polska

CVE-2024-42812

CVSS 9.8v3.1pub. 2024-08-19upd. 2025-03-17

In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

🤖 AI Analysis
How it works

The vulnerability results from the lack of validation of the length of data passed in the SID field handled by the gena.cgi script. An attacker can send a specially crafted request containing an excessively long SID field value, causing a buffer overflow in the device memory. This results in overwriting memory areas controlled by the process, which can lead to taking control of the code execution flow.

Impact

An attacker can cause the device to crash or execute arbitrary commands on the remote target device, gaining full control over the router.

Mitigation & patch

Security patches available from the manufacturer should be applied according to references — information about security updates is available at the D-Link Security Bulletin service (https://www.dlink.com/en/security-bulletin/). In case no update is available, it is recommended to restrict access to the device management interface from external networks and monitor network traffic for anomalies.

Who is affected

D-Link DIR-860L Firmware version 2.03

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 860l

    HW
    Dlink
    all versions
  • Dlink Dir 860l Firmware

    OS
    Dlink
    2.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2018-6530CRITICAL9.8⚠ KEVPL ✓same product

D-Link DIR-860L/865L/868L/880L — command injection przez soap.cgi

CVE-2024-41611CRITICAL9.8PL ✓same product

D-Link DIR-860L: hardcoded credentials w usłudze Telnet umożliwiają RCE

CVE-2018-19987CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822/860L/868L/880L/890L przez HNAP1

CVE-2018-20114CRITICAL9.8PL ✓same product

D-Link DIR-818LW / DIR-860L — nieuwierzytelniony RCE przez command injection w soap.cgi

CVE-2025-9026MEDIUM5.5same product

A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file...