CVE-2024-44674

Published at:
2024-10-07T18:15:04.590

Global infos:

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

CVE Status: Awaiting Analysis

References:

  • [email protected]
  • [email protected]
  • Metrics:

    AttributeValue
    Attack ComplexityLOW
    Attack VectorADJACENT_NETWORK
    Availability ImpactNONE
    Base Score5.7
    Base SeverityMEDIUM
    Confidentiality ImpactNONE
    Integrity ImpactHIGH
    Privileges RequiredLOW
    ScopeUNCHANGED
    User InteractionNONE
    Vector StringCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
    Exploitability Score2.1
    Impact Score3.6
    Source134c704f-9b21-4f2e-91b3-4a467353bcc0
    TypeSecondary

    Links:

    Exploit-db
    Github