PT-2019-6347 · D Link · D-Link Dir-878

Published

2019-02-25

·

Updated

2023-04-26

·

CVE-2019-9125

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-878 version 1.12B01
Description The issue is related to the misuse of the strncpy function, leading to a stack-based buffer overflow. This can be exploited remotely without authentication via the HNAP AUTH HTTP header, potentially affecting the confidentiality, integrity, and availability of protected information.
Recommendations For D-Link DIR-878 version 1.12B01, consider restricting access to the HNAP AUTH HTTP header until a patch is available. As a temporary workaround, avoid using the strncpy function in sensitive areas of the code until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-02833
CVE-2019-9125

Affected Products

D-Link Dir-878