D-Link DIR-825M
cpe:2.3:o:dlink:dir-825_firmware:*:*:*:*:*:*:*
- 1.1.12
A buffer overflow vulnerability has been identified in the D-Link DIR-825M router, specifically in firmware version 1.1.12. The issue arises in the '/boafrm/formWanConfigSetup' endpoint, within the 'sub_414BA8' function. The vulnerability allows remote attackers to manipulate the 'submit-url' parameter, leading to stack memory overwriting. This could cause application crashes, memory corruption, and potentially enable arbitrary code execution on the device.
Exploitation of this vulnerability can cause the router to crash, making the management interface inaccessible. Additionally, it could allow an attacker to execute arbitrary code, potentially taking full control of the device. Such access could be used to monitor network traffic or launch attacks on other devices within the network.
The vulnerability can be reproduced by sending a POST request to the '/boafrm/formWanConfigSetup' endpoint with an oversized 'submit-url' parameter. This can be done using a tool like Burp Repeater. The request should include the necessary headers and cookies to mimic a legitimate user session.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.