ZDI-23-052: D-Link DIR-3040 MiniDLNA Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is ZDI-23-052.
What is the severity of ZDI-23-052?
The severity of ZDI-23-052 is high with a severity value of 8.8.
How does the vulnerability in D-Link DIR-3040 routers allow attackers to execute arbitrary code?
The vulnerability in D-Link DIR-3040 routers allows network-adjacent attackers to execute arbitrary code by exploiting a heap-based buffer overflow in the MiniDLNA service.
Is authentication required to exploit this vulnerability in D-Link DIR-3040 routers?
No, authentication is not required to exploit this vulnerability in D-Link DIR-3040 routers.
Are there any references available for this vulnerability?
Yes, you can find references for this vulnerability at the following links: [Reference 1](http://www.zerodayinitiative.com/advisories/ZDI-23-052/), [Reference 2](https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10322), [Reference 3](https://www.zerodayinitiative.com/advisories/ZDI-23-052/).