Overview
D-Link DIR routers contain a stack-based buffer overflow vulnerability, which may allow a remote attack to execute arbitrary code.
Description
| CWE-121: Stack-based Buffer Overflow - CVE-2016-5681 A stack-based buffer overflow occurs in the function within the cgibin binary which validates the session cookie. 
 | 
Impact
| This function allows a buffer overflow condition in which arbitrary code may be executed. The impact may vary depending on if the use case is local or remote. | 
Solution
| Apply Updates | 
| Restrict Access | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C | 
| Temporal | 8.4 | E:POC/RL:ND/RC:C | 
| Environmental | 6.3 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
Thanks to Daniel Romero @daniel_rome (NCC Group) for reporting this vulnerability.
This document was written by Trent Novelly.
Other Information
| CVE IDs: | CVE-2016-5681 | 
| Date Public: | 2016-08-11 | 
| Date First Published: | 2016-08-11 | 
| Date Last Updated: | 2016-08-12 19:04 UTC | 
| Document Revision: | 17 |