PT-2024-3755 · D Link · D-Link Dir-619L Rev.B

Yubozhaoo

+1

·

Published

2024-05-10

·

Updated

2024-08-08

·

CVE-2024-33771

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-619L Rev.B version 2.06B1
Description The issue is related to a buffer overflow vulnerability in the /bin/boa component of the D-Link DIR-619L Rev.B router, specifically via the "goform/formWPS" endpoint, where the webpage parameter is involved. This vulnerability can be exploited by remote authenticated users to trigger a denial of service (DoS). The vulnerability is also associated with incorrect clearing or release of resources, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For D-Link DIR-619L Rev.B version 2.06B1, consider disabling access to the "goform/formWPS" endpoint as a temporary workaround until a patch is available. Restrict access to the /bin/boa component to minimize the risk of exploitation. Avoid using the webpage parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Improper Resource Release

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-04101
CVE-2024-33771

Affected Products

D-Link Dir-619L Rev.B