PT-2024-8961 · D Link · D-Link Dir-605L

Offshore0315

·

Published

2024-09-26

·

Updated

2024-12-04

·

CVE-2024-11960

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: D-Link DIR-605L version 2.13B01
Description: A critical issue affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to a buffer overflow. This issue can be exploited remotely. The exploit has been disclosed publicly and may be used.
Recommendations: For D-Link DIR-605L version 2.13B01, as a temporary workaround, consider disabling the formSetPortTr function until a patch is available. Restrict access to the /goform/formSetPortTr endpoint to minimize the risk of exploitation. Avoid using the curTime argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-10642
CVE-2024-11960

Affected Products

D-Link Dir-605L