A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
The vulnerability affects the wirelessApcli_5g function handled by the /goform/wirelessApcli_5g endpoint. Manipulation of the apcli_mode_5g, apcli_enc_5g, or apcli_default_key_5g parameters causes a stack-based buffer overflow — user-supplied data is copied to a stack buffer without proper length verification. The attack can be conducted remotely over the network, and the exploit has been publicly disclosed and may be actively exploited.
An attacker can achieve arbitrary code execution on the device (RCE), gain complete control over the router, or cause it to crash. Due to the lack of authentication requirements, this vulnerability poses a serious threat to all devices accessible from the network.
D-Link has not issued and does not plan to issue a patch, as the product has reached End-of-Life status. It is recommended to immediately remove the device from service and replace it with an actively supported model. As interim measures, restrict access to the administrative interface only to trusted local networks and disable remote management on the device.
D-Link DIR-816 with firmware version 1.10CNB05. The device is no longer supported by the manufacturer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dir 816
HWDlinkall versionsDlink Dir 816 Firmware
OSDlink1.10cnb05
Related vulnerabilities
RCE w D-Link DIR-816-A2 przez podatną funkcję system() w goahead
D-Link DIR-816: Stack-based buffer overflow w /goform/form2lansetup.cgi
Stack-based buffer overflow w D-Link DIR-816 – funkcja qosClassifier
Stack-based buffer overflow w D-Link DIR-816 — funkcja QoSPortSetup
D-Link DIR-816: nieautoryzowana zmiana konfiguracji DMZ przez formDMZ.cgi