ZDI-23-1333: D-Link DIR-3040 prog.cgi SetIPv6PppoeSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1333?
ZDI-23-1333 is considered to have a high severity due to its ability to allow arbitrary code execution.
How do I fix ZDI-23-1333?
To mitigate ZDI-23-1333, update the affected D-Link DIR-3040 router firmware to the latest version released by the vendor.
Who is affected by ZDI-23-1333?
ZDI-23-1333 affects installations of D-Link DIR-3040 routers that have not been updated with the latest security fixes.
Can ZDI-23-1333 be exploited remotely?
No, ZDI-23-1333 requires network adjacency, meaning the attacker must be on the same local network to exploit it.
What are the potential impacts of ZDI-23-1333?
The potential impacts of ZDI-23-1333 include unauthorized access and control over the affected router, leading to data breaches or further attacks.