CVE-2024-9549: D-Link DIR-605L formEasySetupWizard formEasySetupWizard2 buffer overflow
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formEasySetupWizard/formEasySetupWizard2 of the file /goform/formEasySetupWizard. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9549?
CVE-2024-9549 is classified as a critical vulnerability.
How does CVE-2024-9549 exploit the D-Link DIR-605L?
CVE-2024-9549 exploits a buffer overflow in the formEasySetupWizard function.
Which version of the D-Link DIR-605L firmware is affected by CVE-2024-9549?
The vulnerability affects the D-Link DIR-605L firmware version 2.13B01.
What can potential attackers achieve with CVE-2024-9549?
Attackers may execute arbitrary code remotely due to the buffer overflow caused by this vulnerability.
Are there any mitigations available for CVE-2024-9549?
Currently, no specific mitigations for CVE-2024-9549 have been publicly recommended.