D-Link DI-7100G
cpe:2.3:h:dlink:di-7100g:*:*:*:*:*:*:*, +1 more
- C1
A buffer overflow vulnerability has been identified in the D-Link DI-7100G router, specifically in the jhttpd service's sub_451754 function. This vulnerability arises from the viav4 parameter, where an excessively long string can lead to a stack overflow. The issue allows attackers to cause a denial-of-service condition or execute arbitrary code on the device.
Exploitation of this vulnerability can lead to a stack-based buffer overflow, allowing for arbitrary code execution or causing a denial-of-service condition on the device.
The vulnerability can be reproduced by sending a crafted HTTP GET request to the '/dbsrv.asp' endpoint. The request must include an excessively long 'str' parameter, which will trigger the buffer overflow in the jhttpd service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.