// For flags

CVE-2014-3936

D-Link HNAP - Request Remote Buffer Overflow

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

Desbordamiento de buffer basado en pila en la función do_hnap en www/my_cgi.cgi en D-Link DSP-W215 (Rev. A1) con firmware 1.01b06 y anteriores, DIR-505 con firmware anterior a 1.08b10 y DIR-505L con firmware 1.01 y anteriores permite a atacantes remotos ejecutar código arbitrario a través de una cabecera Content-Length larga en una acción GetDeviceSettings en una solicitud HNAP.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-06-02 CVE Reserved
  • 2014-06-02 CVE Published
  • 2014-07-14 First Exploit
  • 2024-08-06 CVE Updated
  • 2024-10-25 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dlink
Search vendor "Dlink"
Dir505 Shareport Mobile Companion Firmware
Search vendor "Dlink" for product "Dir505 Shareport Mobile Companion Firmware"
<= 1.07
Search vendor "Dlink" for product "Dir505 Shareport Mobile Companion Firmware" and version " <= 1.07"
-
Affected
in Dlink
Search vendor "Dlink"
Dir505 Shareport Mobile Companion
Search vendor "Dlink" for product "Dir505 Shareport Mobile Companion"
a1
Search vendor "Dlink" for product "Dir505 Shareport Mobile Companion" and version "a1"
-
Affected
Dlink
Search vendor "Dlink"
Dir505l Shareport Mobile Companion Firmware
Search vendor "Dlink" for product "Dir505l Shareport Mobile Companion Firmware"
<= 1.01
Search vendor "Dlink" for product "Dir505l Shareport Mobile Companion Firmware" and version " <= 1.01"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-505l Shareport Mobile Companion
Search vendor "Dlink" for product "Dir-505l Shareport Mobile Companion"
a1
Search vendor "Dlink" for product "Dir-505l Shareport Mobile Companion" and version "a1"
-
Affected
Dlink
Search vendor "Dlink"
Dsp-w215 Firmware
Search vendor "Dlink" for product "Dsp-w215 Firmware"
<= 1.01
Search vendor "Dlink" for product "Dsp-w215 Firmware" and version " <= 1.01"
b06
Affected
in Dlink
Search vendor "Dlink"
Dsp-w215
Search vendor "Dlink" for product "Dsp-w215"
a1
Search vendor "Dlink" for product "Dsp-w215" and version "a1"
-
Affected