CVE-2020-10214: Buffer Overflow
Published Mar 7, 2020
·Updated
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code via a POST to ntpsync.cgi with a sufficiently long parameter ntpserver.
Affected Software
2 affected components
Dlink Dir-825 Firmware=2.10
Dlink DIR-825
Event History
Mar 7, 2020
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-10214.
2
What is the severity level of CVE-2020-10214?
The severity level of CVE-2020-10214 is critical with a CVSS score of 8.8.
3
How does the vulnerability in D-Link DIR-825 Rev.B 2.10 devices occur?
The vulnerability occurs due to a stack-based buffer overflow in the httpd binary of the device.
4
What is the impact of this vulnerability?
The vulnerability allows an authenticated user to execute arbitrary code on the device.
5
Is there a fix available for CVE-2020-10214?
Currently, there is no official fix available for CVE-2020-10214. It is recommended to follow D-Link's security advisories for updates and patches.