PT-2024-7882 · D Link · D-Link Di-8003

Theraz0R

·

Published

2024-08-09

·

Updated

2024-11-15

·

CVE-2024-11047

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DI-8003 version 16.07.16A1
Description A critical issue has been found in the upgrade filter asp function of the /upgrade filter.asp file. The manipulation of the path argument leads to a stack-based buffer overflow. This issue can be exploited remotely. The exploit has been disclosed publicly and may be used.
Recommendations For D-Link DI-8003 version 16.07.16A1, as a temporary workaround, consider disabling the upgrade filter asp function until a patch is available. Restrict access to the /upgrade filter.asp file to minimize the risk of exploitation. Avoid using the path argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-09386
CVE-2024-11047

Affected Products

D-Link Di-8003