D-Link DI-8100
cpe:2.3:h:dlink:di-8100:*:*:*:*:*:*:*, +1 more
- 16.07.26A1
A stack-based buffer overflow vulnerability has been identified in the D-Link DI-8100 router, specifically in the web management interface file '/url_member.asp'. This vulnerability arises from the 'name' parameter, which can be manipulated to overflow a fixed-size stack buffer. The issue can be exploited remotely, potentially leading to memory corruption, a process crash, and allowing for remote code execution.
Exploitation of this vulnerability causes memory corruption and process crashes, with the potential for remote code execution.
To reproduce this vulnerability, log into the router's web interface and navigate to the '/url_member.asp' page. Once there, initiate an 'add' operation by sending a POST request that includes a crafted 'name' parameter. This parameter should contain an excessively long string, which will overflow the stack buffer and trigger the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.