CVE-2017-14948: Buffer Overflow
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENTTYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14948?
The severity of CVE-2017-14948 is critical with a score of 9.8.
Which D-Link products are affected by CVE-2017-14948?
DIR-880L 1.08B04 and DIR-895 L/R 1.13b03 are affected by CVE-2017-14948.
What is the impact of CVE-2017-14948?
The impact of CVE-2017-14948 is the ability to execute arbitrary code remotely.
What is the vulnerable component in CVE-2017-14948?
The vulnerable component in CVE-2017-14948 is htdocs/fileaccess.cgi.
How can an attacker exploit CVE-2017-14948?
An attacker can exploit CVE-2017-14948 by sending a crafted HTTP request to fileaccess.cgi.