A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
The vulnerability exists in the qosClassifier function handling the /goform/qosClassifier endpoint. Manipulation of the dip_address or sip_address arguments allows for stack-based buffer overflow. By providing appropriately crafted input data, an attacker can overwrite stack memory areas, leading to hijacking control of program execution flow. The attack requires no privileges or user interaction.
An attacker can gain full control over the device, potentially executing arbitrary code (RCE) with the privileges of the process handling the request. Complete disabling of device functionality (denial of service) is also possible.
D-Link manufacturer does not plan to release a patch because the product has reached end-of-life support. Immediate replacement with a currently supported model is recommended. As an interim measure, the device should be isolated from the Internet, remote access to the administrative panel should be disabled, and access to the management interface should be restricted to trusted hosts only using a firewall.
D-Link DIR-816 with firmware version 1.10CNB05. The manufacturer no longer provides support for this product.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dir 816
HWDlinkall versionsDlink Dir 816 Firmware
OSDlink1.10cnb05
Related vulnerabilities
RCE w D-Link DIR-816-A2 przez podatną funkcję system() w goahead
D-Link DIR-816: Stack-based buffer overflow w /goform/form2lansetup.cgi
Stack-based buffer overflow w D-Link DIR-816 — zdalny atak bez uwierzytelnienia
Stack-based buffer overflow w D-Link DIR-816 — funkcja QoSPortSetup
D-Link DIR-816: nieautoryzowana zmiana konfiguracji DMZ przez formDMZ.cgi