In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
The vulnerability results from the lack of validation of the length of data passed in the SID field handled by the gena.cgi script. An attacker can send a specially crafted request containing an excessively long SID field value, causing a buffer overflow in the device memory. This results in overwriting memory areas controlled by the process, which can lead to taking control of the code execution flow.
An attacker can cause the device to crash or execute arbitrary commands on the remote target device, gaining full control over the router.
Security patches available from the manufacturer should be applied according to references — information about security updates is available at the D-Link Security Bulletin service (https://www.dlink.com/en/security-bulletin/). In case no update is available, it is recommended to restrict access to the device management interface from external networks and monitor network traffic for anomalies.
D-Link DIR-860L Firmware version 2.03
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 860l
HWDlinkall versionsDlink Dir 860l Firmware
OSDlink2.0.3
Related vulnerabilities
D-Link DIR-860L/865L/868L/880L — command injection przez soap.cgi
D-Link DIR-860L: hardcoded credentials w usłudze Telnet umożliwiają RCE
Command injection w D-Link DIR-822/860L/868L/880L/890L przez HNAP1
D-Link DIR-818LW / DIR-860L — nieuwierzytelniony RCE przez command injection w soap.cgi
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file...