cve/2018/CVE-2018-8941.md
2024-06-09 00:33:16 +00:00

874 B

CVE-2018-8941

Description

Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.

POC

Reference

Github