D-Link DIR-816L
cpe:2.3:h:d-link:dir-816:*:*:*:*:*:*:*, +9 more
- 2_06_b09_beta
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-816L router, specifically in the 2_06_b09_beta firmware version. The issue arises in the 'authenticationcgi_main' function of the 'authentication.cgi' file, where the 'Password' argument can be manipulated, leading to remote exploitation. This vulnerability affects products that are no longer supported by the manufacturer.
Exploitation of this vulnerability allows for a stack-based buffer overflow, which could potentially be used to execute arbitrary code or cause a denial-of-service condition.
The vulnerability can be reproduced by sending a crafted request to the '/authentication.cgi' endpoint, manipulating the 'Password' parameter to exceed the buffer limit. This can be done remotely without any authentication.
Users are advised to implement restrictive firewall rules to block unauthorized access to the router.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.