CVE-2023-32140: D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution Vulnerability
D-Link DAP-1360 webproc var:sysToken Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling requests to the /cgi-bin/webproc endpoint. When parsing the var:sysToken parameter, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-18418.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32140?
CVE-2023-32140 is considered a critical vulnerability due to its potential for remote code execution.
Who is affected by CVE-2023-32140?
CVE-2023-32140 affects users of the D-Link DAP-1360 routers.
How do I fix CVE-2023-32140?
To fix CVE-2023-32140, update the firmware of the D-Link DAP-1360 to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2023-32140?
CVE-2023-32140 is a heap-based buffer overflow vulnerability that allows remote code execution.
Is authentication required to exploit CVE-2023-32140?
No, authentication is not required to exploit CVE-2023-32140, making it particularly dangerous.