CVE-2023-45575

Severity
9.8CRITICAL
EPSS
9.1%
top 7.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip parameter of the ip_position.asp function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

NVDdlink/di-7003g_firmware23.08.25d1
NVDdlink/di-7100g_firmware23.08.23d1
NVDdlink/di-7200g_firmware23.08.23e1

🔴Vulnerability Details

2
CVEList
CVE-2023-45575: Stack Overflow vulnerability in D-Link device DI-7003GV22023-10-16
GHSA
GHSA-49j2-f7c9-w9qc: Buffer Overflow vulnerability in DI-7003GV22023-10-16