CVE-2020-27864
published 2021-02-12CVE-2020-27864: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi…
PriorityP264high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
9.76%
95.0th percentile
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the Authorization request header, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10880.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dap-1860 | — | — |
| dlink | dap-1860_firmware | <= 1.04b03 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests to the HNAP service on TCP port 80 for malformed or oversized Authorization request headers, which is the attack vector for this command injection vulnerability. ↗
- →Target devices are D-Link DAP-1860 WiFi extenders running firmware version 1.04B03; detection should focus on unauthenticated network-adjacent requests to the HNAP service. ↗
- ·The HNAP service listens on TCP port 80 by default, but this port may be reconfigured on some deployments. ↗
- ·Exploitation requires network-adjacent positioning (not remote internet-based); attacker must be on the same network segment or WLAN as the device. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2021-02-12
Published