← Back

CVE-2014-3936

nvd nist
Published: Jun 2, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

Affected (6)

6 products
Dir505 Shareport Mobile Companion
Dsp W215 Firmware
Dsp W215
Configuration A
2 vulnerable
Configuration B
2 vulnerable
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.01
Version a1

References (14)

Timeline

No history available yet.