PT-2021-21628 · D Link · D-Link Dir-615

Published

2021-08-06

·

Updated

2021-08-13

·

CVE-2021-37388

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-615 C2 version 3.03WW
Description A buffer overflow issue exists, allowing an attacker to potentially crash the webserver and gain remote code execution by exploiting the ping ipaddr parameter in the "ping response.cgi" POST request.
Recommendations For D-Link DIR-615 C2 version 3.03WW, as a temporary workaround, consider restricting access to the "ping response.cgi" endpoint until a patch is available. Avoid using the ping ipaddr parameter in the affected POST request to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37388

Affected Products

D-Link Dir-615