SB2016110904 - Remote code execution in D-LINK routers



SB2016110904 - Remote code execution in D-LINK routers

Published: November 9, 2016

Security Bulletin ID SB2016110904
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer overflow (CVE-ID: CVE-2016-6563)

A remote attacker can compromise vulnerable device.

The vulnerability exists due to stack-based buffer overflow when processing Action, Username, LoginPassword, and Captcha fields in XML file. A remote unauthenticated attacker can send a specially crafted SOAP message to HNAPI (Home Network Automation Protocol) login interface, cause stack-based buffer overflow and execute arbitrary code on vulnerable device.

Successful exploitation of the vulnerability may allow an attacker to gain complete control over vulnerable device.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.