ZDI-CAN-21651: ZDI-23-1333: D-Link DIR-3040 prog.cgi SetIPv6PppoeSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21651?
ZDI-CAN-21651 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix ZDI-CAN-21651?
To mitigate ZDI-CAN-21651, users should immediately update their D-Link DIR-3040 routers to the latest firmware version provided by D-Link.
Who is affected by ZDI-CAN-21651?
ZDI-CAN-21651 affects installations of D-Link DIR-3040 routers that are accessible by network-adjacent attackers.
What is the nature of the attack for ZDI-CAN-21651?
The vulnerability allows an authenticated network-adjacent attacker to execute arbitrary code on the affected D-Link DIR-3040 routers.
Is authentication required to exploit ZDI-CAN-21651?
Yes, authentication is required to exploit the ZDI-CAN-21651 vulnerability.