D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
The vulnerability classified as CWE-120 (buffer overflow without size validation) consists of a stack buffer overflow within the sub_451208 function in the router's firmware. An attacker can supply specially crafted input data that exceeds the intended buffer size, overwriting adjacent stack memory areas. Such a mechanism may enable the attacker to gain control over the program's execution flow.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code remotely (RCE) on the device, which may consequently lead to complete takeover of the router, loss of confidentiality, integrity, and availability.
Patches available from the manufacturer should be applied according to the references. If an update is not available, it is recommended to restrict access to the router's management interface exclusively to trusted local networks and disable remote management from the WAN side.
D-Link DIR-820L with firmware version 1.05B03
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 820l
HWDlinkall versionsDlink Dir 820l Firmware
OSDlink1.05b03
Related vulnerabilities
Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root
RCE w D-Link DIR-820L — command injection przez HTTP POST
RCE w routerach D-Link via DDNS — funkcja w pliku binarnym ncc2
Command Injection w narzędziu ping urządzeń D-Link i TRENDnet — RCE bez uwierzytelnienia
D-Link DIR-820L — przepełnienie stosu (stack overflow) w funkcji sub_4507CC