vendor:
DIR-815
by:
Samuel Huntley
N/A
CVSS
N/A
Buffer overflow and Command injection
CWE
Product Name: DIR-815
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
Unknown
DIR-815 Buffer overflows and Command injection in authentication and HNAP functionalities
Have come across 3 security issues in DIR-815 firmware which allows an attacker to exploit command injection and buffer overflows in authentication and HNAP functionality. All of them can be exploited by an unauthenticated attacker. The attacker can be on wireless LAN or WAN if mgmt interface is exposed to attack directly or using XSRF if not exposed.
Mitigation:
The vendor has indicated that they have fixed the issues. Users are advised to update their router firmware.