CVE-2023-45577

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 16, 2023
Updated: Oct 19, 2023
CWE ID 787

Summary

CVE-2023-45577 is a stack overflow vulnerability affecting multiple D-Link device models, including DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before. The issue lies in the H5/speedlimit.data function where a remote attacker can exploit a stack overflow vulnerability by manipulating the wanid parameter, enabling arbitrary code execution. This vulnerability poses a significant risk to affected devices as it allows unauthorized access and potential data breaches. Upgrading to the latest firmware versions is strongly recommended to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share