VulnerabilityModified
CVE-2024-42812
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi.
CRITICAL 9.8EPSS 15.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 15.51% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- dlink/dir-860l firmware
- Source
- cve@mitre.org
References
- https://gist.github.com/XiaoCurry/574ed9c2b0d12cd0b45399116d82121cExploit, Third Party Advisory
- https://www.dlink.com/en/security-bulletin/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.