D-Link DSP-W215
cpe:2.3:h:d-link:dsp-w215:*:*:*:*:*:*:*, +3 more
- 1.02b05
A stack-based buffer overflow vulnerability has been identified in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02. This vulnerability can be exploited by sending a specially crafted HTTP POST request to the /common/info.cgi endpoint. The flaw allows an unauthenticated attacker to execute arbitrary code with system-level privileges on the affected device.
Exploitation of this vulnerability leads to unauthorized remote code execution with system privileges on the affected device.
The vulnerability can be reproduced by sending a POST request to the /common/info.cgi endpoint with a crafted 'storage_path' parameter. The payload must be designed to overflow the stack and overwrite the return address, redirecting execution to a system() call. This can be automated with a Metasploit module that handles the exploitation process.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.