Описание
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.
Ссылки
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:dlink:covr-2600r_firmware:1.01b05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:covr-2600r:-:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.0293
Низкий
5.7 Medium
CVSS3
Дефекты
CWE-121
Связанные уязвимости
CVSS3: 5.7
github
больше 1 года назад
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.
EPSS
Процентиль: 86%
0.0293
Низкий
5.7 Medium
CVSS3
Дефекты
CWE-121