CVE-2024-42812: Buffer Overflow
Published Aug 19, 2024
·Updated
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
Affected Software
2 affected components
All of the following
Dlink Dir-860l Firmware=2.0.3
Dlink Dir-860l
Event History
Aug 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-42812?
CVE-2024-42812 is classified as a high severity buffer overflow vulnerability.
2
How do I fix CVE-2024-42812?
To fix CVE-2024-42812, users should upgrade to a patched version of the D-Link DIR-860L firmware.
3
What causes CVE-2024-42812?
CVE-2024-42812 is caused by the lack of length verification for the SID field in gena.cgi.
4
What can happen if CVE-2024-42812 is exploited?
If exploited, CVE-2024-42812 can lead to a remote device crash or allow execution of arbitrary commands.
5
Which devices are affected by CVE-2024-42812?
CVE-2024-42812 affects the D-Link DIR-860L firmware version 2.0.3.