CVE-2020-26561: Buffer Overflow
UNSUPPORTED WHEN ASSIGNED Belkin LINKSYS WRT160NL 1.0.04.002US20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in createdir in minihttpd. Successful exploitation leads to arbitrary code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26561?
CVE-2020-26561 is a stack-based buffer overflow vulnerability in Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices.
How severe is CVE-2020-26561?
CVE-2020-26561 has a severity rating of 8.8 (high).
How does CVE-2020-26561 occur?
CVE-2020-26561 occurs due to a stack-based buffer overflow vulnerability in the 'create_dir' function in 'mini_httpd' where sprintf is used.
What are the affected products for CVE-2020-26561?
The affected product for CVE-2020-26561 is Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619, specifically those running firmware version 1.0.04-build_2.
Is Belkin LINKSYS WRT160NL vulnerable to CVE-2020-26561?
Belkin LINKSYS WRT160NL devices are vulnerable to CVE-2020-26561 if they are running firmware version 1.0.04-build_2.