CVE-2013-6027: Buffer Overflow
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/toolsmisc.xgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6027?
CVE-2013-6027 is classified as a high severity vulnerability due to its potential for remote code execution.
How does CVE-2013-6027 affect D-Link DIR-100 routers?
CVE-2013-6027 allows remote authenticated administrators to execute arbitrary commands through a stack-based buffer overflow.
How can I mitigate the risk of CVE-2013-6027?
To mitigate CVE-2013-6027, it is recommended to update the D-Link DIR-100 router firmware to a version that addresses this vulnerability.
Can CVE-2013-6027 be exploited without authentication?
No, CVE-2013-6027 requires authentication as a remote administrator to exploit the vulnerability.
What specific parameter is involved in the exploitation of CVE-2013-6027?
The vulnerability is exploited via a long set/runtime/diagnostic/pingIp parameter in the Tools/tools_misc.xgi.