A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dir 825
HWDlinkall versionsDlink Dir 825 Firmware
OSDlink3.00b32
Related vulnerabilities
Buffer overflow w D-Link DIR-825 umożliwiający RCE bez uwierzytelnienia
D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI
Buffer Overflow w D-Link DIR-825 umożliwiający zdalne wykonanie kodu
Auth Bypass w D-Link DIR-825 G1 — nieautoryzowany dostęp do firmware i konfiguracji
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file s...