CVE-2023-45574

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 16, 2023
Updated: Oct 19, 2023
CWE ID 787

Summary

CVE-2023-45574 is a buffer overflow vulnerability affecting multiple D-Link devices, including DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before. An attacker can exploit this issue by sending malicious data to the fn parameter of the file.data function, resulting in a buffer overflow that allows the execution of arbitrary code remotely. This vulnerability poses a significant risk to network security and requires immediate attention from affected device users to apply available patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share