CVE-2018-10713: Buffer Overflow
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'read <nodename>' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability of CVE-2018-10713?
The vulnerability of CVE-2018-10713 allows an authenticated user to cause memory corruption by passing a long buffer as a parameter.
How can an authenticated user exploit CVE-2018-10713?
An authenticated user can exploit CVE-2018-10713 by passing a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary.
What is the severity of CVE-2018-10713?
The severity of CVE-2018-10713 is rated as high with a CVSS score of 8.8.
How can CVE-2018-10713 be fixed?
To fix CVE-2018-10713, it is recommended to update the firmware of the D-Link DSL-3782 device to the latest version provided by the manufacturer.
Is the Dlink DSL-3782 device vulnerable to CVE-2018-10713?
No, the Dlink DSL-3782 device is not vulnerable to CVE-2018-10713.