← Back to CVE List
Vulnerability Intelligence Report

CVE-2017-14948

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:4.80%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
dlink dir-868l_firmware all
dlink dir-868l all
dlink dir-890l_firmware all
dlink dir-890l all
dlink dir-885l_firmware all
dlink dir-885l all
dlink dir-895l_firmware 1.13b03
dlink dir-895l all
dlink dir-880l_firmware 1.08b04
dlink dir-880l all
dlink dir-895r_firmware 1.13b03
dlink dir-895r all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.796%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2017-09-29T00:00:00
Published2019-10-14T17:03:25
Last Updated2024-08-05T19:42:22

LINK COPIED TO CLIPBOARD