SB2016110904 - Remote code execution in D-LINK routers
Published: November 9, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2016-6563)
A remote attacker can compromise vulnerable device.
The vulnerability exists due to stack-based buffer overflow when processing Action, Username, LoginPassword, and Captcha fields in XML file. A remote unauthenticated attacker can send a specially crafted SOAP message to HNAPI (Home Network Automation Protocol) login interface, cause stack-based buffer overflow and execute arbitrary code on vulnerable device.
Successful exploitation of the vulnerability may allow an attacker to gain complete control over vulnerable device.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.