D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_800462c4 in /formAdvFirewall. This vulnerability is triggered via a crafted POST request.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.dlink.com/en/security-bulletin/ | vendor advisory |
https://github.com/Lnkvct/IoT-poc/tree/master/D-Link-DIR809/vuln06 | third party advisory exploit |