CVE-2023-45579
published 2023-10-16CVE-2023-45579: Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1…
PriorityP259critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.24%
65.7th percentile
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip/type parameter of the jingx.asp function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | di-7003g_firmware | <= 23.08.25d1 | — |
| dlink | di-7100g_+_firmware | <= 23.08.23d1 | — |
| dlink | di-7100g_firmware | <= 23.08.23d1 | — |
| dlink | di-7200g_+_firmware | <= 23.08.23d1 | — |
| dlink | di-7200g_firmware | <= 23.08.23e1 | — |
| dlink | di-7300g_+_firmware | <= 23.08.23d1 | — |
| dlink | di-7400g_+_firmware | <= 23.08.23d1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-16
Published