CVE-2023-45577
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wanid parameter of the H5/speedlimit.data function.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.25d1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7003g | Version v2.d1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.23d1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7100g+ | Version v2.d1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.23d1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7100g | Version v2.d1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.23d1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7200g+ | Version v2.d1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.23e1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7200g | Version v2.e1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.23d1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7300g+ | Version v2.d1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 23.08.23d1 |
| Running on/with | Platform Versions |
|---|---|
Dlink Di 7400g+ | Version v2.d1 |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.