vendor:
DIR-890L/R
by:
Samuel Huntley
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: DIR-890L/R
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: None
CPE: h:dlink:dir-890l_r
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2015
DIR-890L/R Buffer overflows in authentication and HNAP functionalities.
Two buffer overflows in authentication and HNAP functionalities of DIR-890L/R can be exploited by an unauthenticated attacker. The attacker can be on wireless LAN or WAN if the management interface is exposed to attack directly or using XSRF if not exposed. The exploit needs to be run at least 200-500 times to bypass ASLR on ARM based devices. The buffer overflow happens in a separate process than the web server which does not allow the web server to crash and hence the attacker wins.
Mitigation:
Update the router firmware to the latest version.