9.8

CVE-2016-5681

Medienbericht
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dlink ≫ Dir-868l Firmware Version <= 2.03
   Dlink ≫ Dir-868l Version b1
Dlink ≫ Dir-822 Firmware Version 3.01
   Dlink ≫ Dir-822 Version a1
D-link ≫ Dir-880l Firmware Version <= 1.07
   Dlink ≫ Dir-880l Version a1
D-link ≫ Dir-850l Firmare Version <= 2.07
   Dlink ≫ Dir-850l Version b1
D-link ≫ Dir-895l Firmware Version <= 1.11
   Dlink ≫ Dir-895l Version a1
D-link ≫ Dir-890l Firmware Version <= 1.09
   Dlink ≫ Dir-890l Version a1
D-link ≫ Dir-823 Firmware Version <= 1.00
   Dlink ≫ Dir-823 Version a1
D-link ≫ Dir-885l Firmware Version <= 1.11
   Dlink ≫ Dir-885l Version a1
Dlink ≫ Dir-868l Firmware Version <= 3.00
   Dlink ≫ Dir-868l Version c1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.93% 0.956
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.06.2026 16:38
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.06.2026 16:38
http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10063
Vendor Advisory
http://www.kb.cert.org/vuls/id/332115
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/92427
Third Party Advisory
VDB Entry