CVE-2018-20305: Buffer Overflow
D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this D-Link DIR-816 A2 firmware vulnerability?
The vulnerability ID for this D-Link DIR-816 A2 firmware vulnerability is CVE-2018-20305.
What is the severity level of CVE-2018-20305?
The severity level of CVE-2018-20305 is critical with a score of 9.8.
How does this vulnerability allow remote code execution?
This vulnerability allows arbitrary remote code execution without authentication via the newpass parameter in the /goform/form2userconfig.cgi handler function.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a long password that triggers a stack-based buffer overflow and overwrites a return address.
Is there a fix available for CVE-2018-20305?
Currently, there is no information available regarding a fix for CVE-2018-20305. It is recommended to follow the vendor's security advisories for any updates.