ZDI-CAN-21650: ZDI-23-1332: D-Link DIR-3040 prog.cgi SetDeviceSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21650?
The ZDI-CAN-21650 vulnerability is classified as a high severity issue due to its ability to allow arbitrary code execution.
How do I fix ZDI-CAN-21650?
To resolve the ZDI-CAN-21650 vulnerability, users should update the firmware of their D-Link DIR-3040 routers to the latest version available from the manufacturer.
Who is affected by ZDI-CAN-21650?
The ZDI-CAN-21650 vulnerability affects installations of D-Link DIR-3040 routers that have not been patched.
Is authentication required to exploit ZDI-CAN-21650?
Yes, exploiting the ZDI-CAN-21650 vulnerability requires authentication to the affected D-Link DIR-3040 router.
What kind of attack does ZDI-CAN-21650 enable?
The ZDI-CAN-21650 vulnerability enables network-adjacent attackers to execute arbitrary code on the affected D-Link DIR-3040 routers.