D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://d-link.com | product |
https://www.dlink.com/en/security-bulletin/ | vendor advisory |
http://dir-2640-us.com | url repurposed product |
https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-34201 | third party advisory exploit |