First published: Mon Oct 16 2023(Updated: )
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wild/mx and other parameters of the ddns.asp function
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Di-7003g Firmware | <=23.08.25d1 | |
Dlink Di-7003g | =v2.d1 | |
Dlink Di-7100g\+ Firmware | <=23.08.23d1 | |
Dlink Di-7100g\+ | =v2.d1 | |
Dlink Di-7100g Firmware | <=23.08.23d1 | |
Dlink Di-7100g | =v2.d1 | |
Dlink Di-7200g\+ Firmware | <=23.08.23d1 | |
Dlink Di-7200g\+ | =v2.d1 | |
Dlink Di-7200g Firmware | <=23.08.23e1 | |
Dlink Di-7200g | =v2.e1 | |
Dlink Di-7300g\+ Firmware | <=23.08.23d1 | |
Dlink Di-7300g\+ | =v2.d1 | |
Dlink Di-7400g\+ Firmware | <=23.08.23d1 | |
Dlink Di-7400g\+ | =v2.d1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-45580 is critical with a score of 9.8.
The D-Link devices affected by CVE-2023-45580 are DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1.
A buffer overflow vulnerability occurs when a program tries to store more data in a buffer than it can handle, leading to the overwriting of adjacent memory.
The buffer overflow vulnerability in D-Link devices can be exploited by an attacker sending specially crafted data to the affected device, potentially allowing them to execute arbitrary code or gain unauthorized access.
To mitigate the buffer overflow vulnerability in D-Link devices, it is recommended to update the firmware to a version that includes a fix for the vulnerability.