CVE-2016-1558
Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, and DAP-3662 1.01 and earlier allows remote attackers to have unspecified impact via a crafted 'dlink_uid' cookie.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.10% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- dlink/dap-3662 firmware · dlink/dap-2310 firmware · dlink/dap-2330 firmware · dlink/dap-2360 firmware · dlink/dap-2553 firmware · dlink/dap-2660 firmware · dlink/dap-2690 firmware · dlink/dap-2695 firmware · dlink/dap-3320 firmware · dlink/dap-2230 firmware
- Source
- cret@cert.org
References
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.htmlBroken Link, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/112Mailing List, Third Party Advisory
- http://www.dlink.com/mk/mk/support/support-news/2016/march/16/firmadyne-cve_2016_1558-cve_2016_1559Patch, Vendor Advisory
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.htmlBroken Link, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/112Mailing List, Third Party Advisory
- http://www.dlink.com/mk/mk/support/support-news/2016/march/16/firmadyne-cve_2016_1558-cve_2016_1559Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.