D-Link Dsl-3782 Firmware vulnerabilities

7 known vulnerabilities affecting d-link/dsl-3782_firmware.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7

Vulnerabilities

Page 1 of 1
CVE-2018-10746HIGHCVSS 8.8v1.012018-05-04
CVE-2018-10746 [HIGH] CWE-119 CVE-2018-10746: An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long bu An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'get ' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
nvd
CVE-2018-10750HIGHCVSS 8.8v1.012018-05-04
CVE-2018-10750 [HIGH] CWE-119 CVE-2018-10750: An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long bu An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'staticGet ' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
nvd
CVE-2018-10749HIGHCVSS 8.8v1.012018-05-04
CVE-2018-10749 [HIGH] CWE-119 CVE-2018-10749: An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long bu An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'commit ' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
nvd
CVE-2018-10748HIGHCVSS 8.8v1.012018-05-04
CVE-2018-10748 [HIGH] CWE-119 CVE-2018-10748: An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long bu An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'show ' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
nvd
CVE-2018-10747HIGHCVSS 8.8v1.012018-05-04
CVE-2018-10747 [HIGH] CWE-119 CVE-2018-10747: An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long bu An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'unset ' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
nvd
CVE-2018-10713HIGHCVSS 8.8v1.012018-05-03
CVE-2018-10713 [HIGH] CWE-119 CVE-2018-10713: An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long bu An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'read ' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.
nvd
CVE-2018-8941HIGHCVSS 8.8v1.012018-04-03
CVE-2018-8941 [HIGH] CWE-119 CVE-2018-8941: Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.
nvd