D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DIR-823G | product |
https://github.com/n0wstr/IOTVuln/tree/main/DIR-823g/UploadFirmware | third party advisory exploit |