PT-2023-6460 · D Link · Di-7003Gv2.D1+5

Published

2023-10-16

·

Updated

2023-10-19

·

CVE-2023-45576

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DI-7003GV2.D1 versions 23.08.25D1 and earlier D-Link DI-7100G+V2.D1 versions 23.08.23D1 and earlier D-Link DI-7100GV2.D1 version 23.08.23D1 D-Link DI-7200G+V2.D1 versions 23.08.23D1 and earlier D-Link DI-7200GV2.E1 versions 23.08.23E1 and earlier D-Link DI-7300G+V2.D1 version 23.08.23D1 D-Link DI-7400G+V2.D1 versions 23.08.23D1 and earlier
Description The issue is related to a Buffer Overflow in the upnp ctrl.asp function, allowing a remote attacker to execute arbitrary code via the remove ext proto and remove ext port parameters. This can enable an attacker to perform unauthorized actions on the affected devices.
Recommendations For D-Link DI-7003GV2.D1 versions 23.08.25D1 and earlier, update to a version later than 23.08.25D1. For D-Link DI-7100G+V2.D1 versions 23.08.23D1 and earlier, update to a version later than 23.08.23D1. For D-Link DI-7100GV2.D1 version 23.08.23D1, update to a version later than 23.08.23D1. For D-Link DI-7200G+V2.D1 versions 23.08.23D1 and earlier, update to a version later than 23.08.23D1. For D-Link DI-7200GV2.E1 versions 23.08.23E1 and earlier, update to a version later than 23.08.23E1. For D-Link DI-7300G+V2.D1 version 23.08.23D1, update to a version later than 23.08.23D1. For D-Link DI-7400G+V2.D1 versions 23.08.23D1 and earlier, update to a version later than 23.08.23D1. As a temporary workaround, consider disabling the upnp ctrl.asp function until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07179
CVE-2023-45576

Affected Products

Di-7003Gv2.D1
Di-7100Gv2.D1
Di-7200G+V2.D1
Di-7200Gv2.E1
Di-7300G+V2.D1
Di-7400G+V2.D1