CVE-2024-7849: D-Link DNS-1550-04 photocenter_mgr.cgi cgi_create_album buffer overflow
UNSUPPORTED WHEN ASSIGNED A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This affects the function cgicreatealbum of the file /cgi-bin/photocentermgr.cgi. The manipulation of the argument currentpath leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7849?
CVE-2024-7849 has been classified as a critical vulnerability.
How do I fix CVE-2024-7849?
To mitigate CVE-2024-7849, ensure your D-Link device firmware is updated to version released after August 14, 2024.
What devices are affected by CVE-2024-7849?
CVE-2024-7849 affects multiple D-Link devices including models such as DNS-120, DNS-320, and DNR-202L among others.
What type of vulnerability is CVE-2024-7849?
CVE-2024-7849 is a critical vulnerability that poses security risks to its affected devices.
Is there a workaround for CVE-2024-7849?
Currently, the best practice for CVE-2024-7849 is to upgrade to the latest firmware that addresses the vulnerability.