CVE-2024-33345

Severity
6.5MEDIUM
EPSS
0.5%
top 36.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 29

Description

D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2024-33345: D-Link DIR-823G A1V12024-04-29
GHSA
GHSA-4qmm-8p43-6vrx: D-Link DIR-823G A1V12024-04-29
CVE-2024-33345 (MEDIUM CVSS 6.5) | D-Link DIR-823G A1V1.0.2B05 was fou | cvebase.io