CVE-2020-9276: Buffer Overflow
An issue was discovered on D-Link DSL-2640B B2 EU4.01B devices. The function docgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stack-based buffer overflow. Unauthenticated exploitation is possible by combining this vulnerability with CVE-2020-9277.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9276?
CVE-2020-9276 has a critical severity level due to its potential for remote exploitation.
How do I fix CVE-2020-9276?
To fix CVE-2020-9276, update the D-Link DSL-2640B firmware to the latest version provided by D-Link.
What devices are affected by CVE-2020-9276?
CVE-2020-9276 specifically affects D-Link DSL-2640B devices running firmware version EU_4.01B.
Can CVE-2020-9276 be exploited remotely?
Yes, CVE-2020-9276 can be exploited remotely without authentication.
What type of vulnerability is CVE-2020-9276?
CVE-2020-9276 is a stack-based buffer overflow vulnerability that affects the do_cgi() function on the device.