ZDI-23-1326: D-Link DIR-3040 prog.cgi SetWan3Settings Stack-Based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1326?
The vulnerability ZDI-23-1326 has a high severity level due to the ability of network-adjacent attackers to execute arbitrary code.
How do I fix ZDI-23-1326?
To fix vulnerability ZDI-23-1326, update the firmware of your D-Link DIR-3040 router to the latest version provided by the vendor.
What type of attacks can ZDI-23-1326 facilitate?
Vulnerability ZDI-23-1326 can facilitate arbitrary code execution attacks by authenticated network-adjacent attackers.
Who is affected by ZDI-23-1326?
ZDI-23-1326 affects installations of the D-Link DIR-3040 router that have not been updated to the patched firmware version.
Is authentication required to exploit ZDI-23-1326?
Yes, authentication is required to exploit vulnerability ZDI-23-1326, making it accessible only to attackers who can access the network.