PT-2024-3753 · D Link · D-Link Dir-619L
Yubozhaoo
+1
·
Published
2024-05-10
·
Updated
2024-08-20
·
CVE-2024-33774
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
D-Link DIR-619L versions 2.06B1
Description:
The issue is related to a buffer overflow in the formWlanSetup Wizard function of the D-Link DIR-619L router's firmware. This can be exploited by a remote attacker to cause a denial of service using the
webpage parameter in the /bin/boa endpoint.Recommendations:
For version 2.06B1, consider disabling the formWlanSetup Wizard function as a temporary workaround until a patch is available. Restrict access to the /bin/boa endpoint to minimize the risk of exploitation. Avoid using the
webpage parameter in the affected endpoint until the issue is resolved.Exploit
Fix
Resource Exhaustion
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-619L