ZDI-23-534: D-Link DAP-1360 webproc var:page Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-534?
The severity of ZDI-23-534 is high due to the potential for arbitrary code execution without authentication.
How do I fix ZDI-23-534?
To fix ZDI-23-534, update the firmware of the D-Link DAP-1360 router to the latest version provided by D-Link.
Who is affected by ZDI-23-534?
Any user of D-Link DAP-1360 routers with vulnerable firmware is affected by ZDI-23-534.
Can ZDI-23-534 be exploited remotely?
ZDI-23-534 requires network-adjacent access, meaning an attacker must be on the same local network to exploit it.
What are the potential impacts of ZDI-23-534?
The potential impacts of ZDI-23-534 include unauthorized access and control over the affected router, leading to further network breaches.