PT-2025-3435 · D Link · Dsr-150+4

Published

2024-11-18

·

Updated

2025-07-01

·

CVE-2024-57376

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DSR-150 versions 3.13 through 3.17B901C D-Link DSR-150N versions 3.13 through 3.17B901C D-Link DSR-250 versions 3.13 through 3.17B901C D-Link DSR-250N versions 3.13 through 3.17B901C D-Link DSR-500N versions 3.13 through 3.17B901C D-Link DSR-1000N versions 3.13 through 3.17B901C
Description The issue allows unauthenticated users to execute remote code. This is due to a buffer overflow vulnerability.
Recommendations For D-Link DSR-150 versions 3.13 through 3.17B901C, consider disabling remote access until a patch is available. For D-Link DSR-150N versions 3.13 through 3.17B901C, consider disabling remote access until a patch is available. For D-Link DSR-250 versions 3.13 through 3.17B901C, consider disabling remote access until a patch is available. For D-Link DSR-250N versions 3.13 through 3.17B901C, consider disabling remote access until a patch is available. For D-Link DSR-500N versions 3.13 through 3.17B901C, consider disabling remote access until a patch is available. For D-Link DSR-1000N versions 3.13 through 3.17B901C, consider disabling remote access until a patch is available.

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-01853
CVE-2024-57376

Affected Products

Dsr-1000N
Dsr-150
Dsr-250
Dsr-250N
Dsr-500N