ZDI-23-1325: D-Link DIR-3040 prog.cgi SetQuickVPNSettings Password Stack-Based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1325?
The severity of ZDI-23-1325 is critical as it allows network-adjacent attackers to execute arbitrary code on vulnerable D-Link DIR-3040 routers.
How do I fix ZDI-23-1325?
To fix ZDI-23-1325, users should apply the latest firmware updates provided by D-Link for the DIR-3040 router.
What type of attack is associated with ZDI-23-1325?
ZDI-23-1325 is associated with remote code execution attacks, which can be exploited by authenticated network-adjacent attackers.
Is authentication required to exploit ZDI-23-1325?
Yes, authentication is required to exploit the ZDI-23-1325 vulnerability in D-Link DIR-3040 routers.
Which devices are affected by ZDI-23-1325?
D-Link DIR-3040 routers with vulnerable firmware versions are affected by ZDI-23-1325.