D-Link DIR-600L
cpe:2.3:h:d-link:dir-600:*:*:*:*:*:*:*, +6 more
- <= 2.07B01
A critical buffer overflow vulnerability has been identified in the D-Link DIR-600L router, affecting versions through 2.07B01. The issue arises in the formSetLog function, where improper handling of the 'host' argument creates a buffer overflow condition. This vulnerability can be exploited remotely and impacts products that are no longer supported by the manufacturer.
Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition.
The vulnerability can be reproduced by sending a crafted request to the DIR-600L router's formSetLog function, including a 'host' argument that exceeds the buffer's capacity. This can be done remotely, taking advantage of the router's exposed web interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.