PT-2023-3479 · D Link · D-Link Dir-823G
Published
2023-02-27
·
Updated
2023-07-06
·
CVE-2023-26612
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823G firmware version 1.02B05
Description
The issue is related to a buffer overflow in the implementation of the HNAP1 protocol in the D-Link DIR-823G router's firmware. This occurs when processing the
SetParentsControlInfo parameter, specifically the HostName field. Exploitation of this issue could allow a remote attacker to cause a denial of service.Recommendations
For D-Link DIR-823G firmware version 1.02B05, consider disabling the
SetParentsControlInfo function until a patch is available to prevent potential exploitation. Restrict access to the vulnerable HostName field in the SetParentsControlInfo parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-823G