CVE-2021-26709: Buffer Overflow
UNSUPPORTED WHEN ASSIGNED D-Link DSL-320B-D1 devices through EU1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26709?
CVE-2021-26709 is a vulnerability in the D-Link DSL-320B-D1 devices through EU_1.25 that allows unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters.
How severe is CVE-2021-26709?
CVE-2021-26709 has a severity rating of 9.8 out of 10, which is considered critical.
How can an attacker exploit CVE-2021-26709?
An attacker can exploit CVE-2021-26709 by sending malicious login.xgi user and pass parameters to the affected D-Link DSL-320B-D1 devices through EU_1.25, allowing them to take over the device remotely.
Which D-Link devices are affected by CVE-2021-26709?
The vulnerability CVE-2021-26709 affects D-Link DSL-320B-D1 devices through EU_1.25.
Is there a fix available for CVE-2021-26709?
As this vulnerability is no longer supported, there may not be an official fix available for CVE-2021-26709. It is recommended to update to a supported device or seek guidance from the vendor.