D-Link DIR600L
cpe:2.3:h:d-link:dir-600l:*:*:*:*:*:*:*, +3 more
- FW116WWb01
A buffer overflow vulnerability has been identified in the D-Link DIR-600L A1 router, specifically in the firmware version FW116WWb01. The issue arises in the function 'formSetWAN_Wizard7', where the 'curTime' parameter is processed. The vulnerability allows for arbitrary memory manipulation, which could potentially be exploited to execute arbitrary code or cause a denial-of-service condition.
Exploitation of this vulnerability leads to a buffer overflow, allowing for arbitrary memory manipulation. This could be used to execute arbitrary code or cause a denial-of-service condition by crashing the device.
The vulnerability can be reproduced by sending a crafted request to the 'formSetWAN_Wizard7' function, including an overly long 'curTime' parameter. The 'sprintf' function used in this context does not validate the length of the input, causing the buffer overflow.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.