vendor:
DIR-645 Whole Home Router 1000
by:
Samuel Huntley
8,8
CVSS
HIGH
Buffer Overflow and Command Injection
78, 120
CWE
Product Name: DIR-645 Whole Home Router 1000
Affected Version From: DIR-645 firmware
Affected Version To: DIR-645 firmware
Patch Exists: YES
Related CWE: None
CPE: h:dlink:dir-645
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MIPS little endian architecture
2020
Dlink DIR-645 UPNP Buffer Overflow
The buffer overflow exploit allows an attacker on wireless LAN and possibly WAN network to execute command injection and buffer overflow attack against the wireless router. The buffer overflow does not have a payload at this time, however if you watch the exploit in a debugger, then it can be clearly seen that the payload uses ROP techniques to get to stack payload which is a bunch of C's for now on the stack. It can be replaced with any payload that works on MIPS little endian architecture.
Mitigation:
Users should update the router firmware to the latest version to mitigate the vulnerability.