PT-2023-6596 · D Link · Di-7003Gv2.D1+5
Published
2023-10-16
·
Updated
2023-10-19
·
CVE-2023-45577
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DI-7003GV2.D1 versions 23.08.25D1 and earlier
D-Link DI-7100G+V2.D1 versions 23.08.23D1 and earlier
D-Link DI-7100GV2.D1 version 23.08.23D1
D-Link DI-7200G+V2.D1 versions 23.08.23D1 and earlier
D-Link DI-7200GV2.E1 versions 23.08.23E1 and earlier
D-Link DI-7300G+V2.D1 version 23.08.23D1
D-Link DI-7400G+V2.D1 versions 23.08.23D1 and earlier
Description
The issue is related to a buffer overflow in the H5/speedlimit.data function of D-Link device firmware, allowing a remote attacker to execute arbitrary code via the
wanid parameter. This can enable a remote attacker to perform unauthorized actions.Recommendations
For D-Link DI-7003GV2.D1 versions 23.08.25D1 and earlier, update to a version later than 23.08.25D1.
For D-Link DI-7100G+V2.D1 versions 23.08.23D1 and earlier, update to a version later than 23.08.23D1.
For D-Link DI-7100GV2.D1 version 23.08.23D1, update to a version later than 23.08.23D1.
For D-Link DI-7200G+V2.D1 versions 23.08.23D1 and earlier, update to a version later than 23.08.23D1.
For D-Link DI-7200GV2.E1 versions 23.08.23E1 and earlier, update to a version later than 23.08.23E1.
For D-Link DI-7300G+V2.D1 version 23.08.23D1, update to a version later than 23.08.23D1.
For D-Link DI-7400G+V2.D1 versions 23.08.23D1 and earlier, update to a version later than 23.08.23D1.
As a temporary workaround, consider restricting access to the H5/speedlimit.data function until a patch is available. Avoid using the
wanid parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Di-7003Gv2.D1
Di-7100Gv2.D1
Di-7200G+V2.D1
Di-7200Gv2.E1
Di-7300G+V2.D1
Di-7400G+V2.D1