Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrvx-v9w9-54rr

Опубликовано: 29 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.9
CVSS3: 9.8

Описание

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 21%
0.00066
Низкий

8.9 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость функции sess_get_uid() микропрограммного обеспечения маршрутизаторов D-Link DIR-600, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 21%
0.00066
Низкий

8.9 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-119