An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.dlink.com/en/security-bulletin/ | product |
https://github.com/hhhhu8045759/619L_upnpd_heapoverflow | third party advisory exploit |