PT-2014-1985 · D Link · Dnr-322L+4

Published

2014-07-30

·

Updated

2023-04-26

·

CVE-2014-7859

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Link DNR-320L versions prior to 1.04b08 D-Link DNS-320LW versions prior to 1.04b08 D-Link DNR-322L versions prior to 2.10 build 03 D-Link DNR-326 versions prior to 2.10 build 03 D-Link DNS-327L versions prior to 1.04b01
Description The issue is caused by a stack-based buffer overflow in the login mgr.cgi component of the D-Link firmware. This can be exploited by a remote attacker to execute arbitrary code by crafting malformed Host and Referer header values.
Recommendations For D-Link DNR-320L versions prior to 1.04b08, update to version 1.04b08 or later. For D-Link DNS-320LW versions prior to 1.04b08, update to version 1.04b08 or later. For D-Link DNR-322L versions prior to 2.10 build 03, update to version 2.10 build 03 or later. For D-Link DNR-326 versions prior to 2.10 build 03, update to version 2.10 build 03 or later. For D-Link DNS-327L versions prior to 1.04b01, update to version 1.04b01 or later. As a temporary workaround, consider restricting access to the login mgr.cgi component until a patch is available. Avoid using the login mgr.cgi component with untrusted input for the Host and Referer headers.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2017-02412
CVE-2014-7859

Affected Products

Dnr-320L
Dnr-322L
Dnr-326
Dns-320L
Dns-327L