CVE-2017-14948

Severity
9.8CRITICAL
EPSS
3.0%
top 13.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateMay 24

Description

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-6447-8xgh-93jm: Certain D-Link products are affected by: Buffer Overflow2022-05-24
CVEList
CVE-2017-14948: Certain D-Link products are affected by: Buffer Overflow2019-10-14
CVE-2017-14948 (CRITICAL CVSS 9.8) | Certain D-Link products are affecte | cvebase.io