PoC Index

CVE-2014-3936

HIGH 10.0EPSS 76.6%

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
76.55% chance of exploitation in the next 30 days, 100th percentile
Published
2014-06-02
Updated
2024-08-06

Metasploit modules (1)

ExploitDB entries (1)

References

Related