D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP protocol message, which is mishandled in /usr/sbin/udhcpd during reading of the /var/servd/LAN-1-udhcpd.conf file.
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
Link | Tags |
---|---|
https://github.com/pr0v3rbs/CVE/tree/master/CVE-2019-6258 | third party advisory exploit |
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10175 | patch vendor advisory |