D-Link DI-8003
cpe:2.3:h:dlink:di-8003:*:*:*:*:*:*:*, +1 more
- 16.07.26A1
A buffer overflow vulnerability has been identified in the D-Link DI-8003 router, specifically in version 16.07.26A1. The vulnerability arises from improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this issue by sending a crafted HTTP GET request that includes the parameters name, en, ips, u, time, act, rpri, and log.
Exploitation of this vulnerability leads to a stack-based buffer overflow, causing a denial-of-service condition on the device.
To reproduce this vulnerability, send an HTTP GET request to the /url_rule.asp endpoint with crafted values that exceed the buffer size for the name, en, ips, u, time, act, rpri, and log parameters. The excessive length of these parameters will trigger the buffer overflow.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.