vendor:
DIR-866L
by:
Samuel Huntley
8,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DIR-866L
Affected Version From: 1.03
Affected Version To: 1.05
Patch Exists: YES
Related CWE: None
CPE: o:d-link:dir-866l_firmware
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
DIR-866L Buffer overflows in HNAP and send email functionalities
Have come across 2 security issue in DIR866L firmware which allows an attacker on wireless LAN to exploit buffer overflow vulnerabilities in hnap and send email functionalities. An attacker needs to be on wireless LAN or management interface needs to be exposed on Internet to exploit HNAP vulnerability but it requires no authentication. The send email buffer overflow does require the attacker to be on wireless LAN or requires to trick administrator to exploit using XSRF.
Mitigation:
Upgrade to the latest firmware version.