First published: Mon Oct 14 2019(Updated: )
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-868L Firmware | ||
D-Link DIR-868LW | ||
D-Link DIR-890L Firmware | ||
D-Link DIR-890L Firmware | ||
D-Link DIR-885L Firmware | ||
Dlink DIR-885L MFC | ||
D-Link DIR-895L Firmware | =1.13b03 | |
D-Link DIR-895L Firmware | ||
D-Link DIR-880L Firmware | =1.08b04 | |
D-Link DIR-880L Firmware | ||
D-Link DIR-895R Firmware | =1.13b03 | |
D-Link DIR-895R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-14948 is critical with a score of 9.8.
DIR-880L 1.08B04 and DIR-895 L/R 1.13b03 are affected by CVE-2017-14948.
The impact of CVE-2017-14948 is the ability to execute arbitrary code remotely.
The vulnerable component in CVE-2017-14948 is htdocs/fileaccess.cgi.
An attacker can exploit CVE-2017-14948 by sending a crafted HTTP request to fileaccess.cgi.