← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-3936

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:76.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
dlink dir505_shareport_mobile_companion_firmware all
dlink dir505_shareport_mobile_companion a1
dlink dir505l_shareport_mobile_companion_firmware all
dlink dir-505l_shareport_mobile_companion a1
dlink dsp-w215_firmware all
dlink dsp-w215 a1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
76.555%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2014-06-02T00:00:00
Published2014-06-02T14:00:00
Patch Date2014-05-15
Last Updated2024-08-06T10:57:17

LINK COPIED TO CLIPBOARD