First published: Tue Apr 03 2018(Updated: )
Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dsl-3782 Firmware | =1.01 | |
Dlink Dsl-3782 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-8941 is critical.
The vulnerability in CVE-2018-8941 occurs due to a buffer overflow in the Diagnostics functionality of D-Link DSL-3782 devices.
An authenticated remote attacker can execute arbitrary code by exploiting the buffer overflow in CVE-2018-8941.
D-Link DSL-3782 devices with firmware EU v. 1.01 are affected by CVE-2018-8941.
There is currently no available fix for CVE-2018-8941. It is recommended to contact the vendor for any available patches or updates.