PT-2023-6459 · D Link · Di-7400G+V2+4

CVE-2023-45572

·

Published

2023-10-16

·

Updated

2024-02-20

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DI-7003GV2 versions 23.08.25D1 and before D-Link DI-7100G+V2 versions 23.08.23D1 and before D-Link DI-7100GV2 version 23.08.23D1 D-Link DI-7200G+V2 versions 23.08.23D1 and before D-Link DI-7200GV2 versions 23.08.23E1 and before D-Link DI-7300G+V2 version 23.08.23D1 D-Link DI-7400G+V2 versions 23.08.23D1 and before
Description The issue is related to a Buffer Overflow vulnerability in the tgfile.htm function of D-Link devices, which allows a remote attacker to execute arbitrary code via the fn parameter. This can be exploited by a remote attacker to gain unauthorized access and execute arbitrary code.
Recommendations For D-Link DI-7003GV2 versions 23.08.25D1 and before, update to a version later than 23.08.25D1. For D-Link DI-7100G+V2 versions 23.08.23D1 and before, update to a version later than 23.08.23D1. For D-Link DI-7100GV2 version 23.08.23D1, update to a version later than 23.08.23D1. For D-Link DI-7200G+V2 versions 23.08.23D1 and before, update to a version later than 23.08.23D1. For D-Link DI-7200GV2 versions 23.08.23E1 and before, update to a version later than 23.08.23E1. For D-Link DI-7300G+V2 version 23.08.23D1, update to a version later than 23.08.23D1. For D-Link DI-7400G+V2 versions 23.08.23D1 and before, update to a version later than 23.08.23D1. As a temporary workaround, consider disabling the tgfile.htm function until a patch is available. Restrict access to the fn parameter in the tgfile.htm function to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07178
CVE-2023-45572

Affected Products

Di-7003Gv2
Di-7100Gv2
Di-7200Gv2
Di-7300G+V2
Di-7400G+V2