vendor:
DIR-880L
by:
Samuel Huntley
8,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: DIR-880L
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: None
CPE: h:dlink:dir-880l
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Wireless LAN or WAN
2020
DIR-880L Buffer overflows in authenticatio and HNAP functionalities.
An unauthenticated attacker can exploit buffer overflows in authentication and HNAP functionalities by running the exploit at least 200-500 times to bypass ASLR on ARM based devices. The exploit works as the buffer overflow happens in a separate process than the web server which does not allow the web server to crash and hence the attacker wins.
Mitigation:
Update the router firmware to the latest version.