D-Link DIR-619L
cpe:2.3:h:d-link:dir-619l:*:*:*:*:*:*:*, +2 more
- 2.04B04
A critical buffer overflow vulnerability has been identified in the D-Link DIR-619L router, specifically in version 2.04B04. The issue arises in the formSetWizard2 function, where improper handling of the curTime argument creates a buffer overflow condition. This vulnerability can be exploited remotely and affects devices that are no longer supported by the vendor.
Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition on the device.
The vulnerability can be reproduced by sending a crafted request to the DIR-619L router's formSetWizard2 function, including a payload that exceeds the buffer size allocated for the curTime argument. This can be done remotely, taking advantage of the router's web interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.