On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://www.dlink.com/en/security-bulletin/ | product |
https://github.com/whokilleddb/dlink-dir-819-dos | third party advisory exploit |
http://packetstormsecurity.com/files/171484/D-Link-DIR-819-A1-Denial-Of-Service.html | exploit vdb entry third party advisory |