CVE-2023-45574Out-of-bounds Write in Dlink Di-7100g + Firmware

Severity
9.8CRITICALNVD
EPSS
22.6%
top 4.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

NVDdlink/di-7003g_firmware23.08.25d1
NVDdlink/di-7100g_firmware23.08.23d1
NVDdlink/di-7200g_firmware23.08.23e1

🔴Vulnerability Details

2
GHSA
GHSA-v697-7hq7-978f: Buffer Overflow vulnerability in DI-7003GV22023-10-16
CVEList
CVE-2023-45574: Buffer Overflow vulnerability in D-Link device DI-7003GV22023-10-16
CVE-2023-45574 — Out-of-bounds Write in Dlink | cvebase