CyberSec.Space Logo
CVEブラウザに戻る

CVE-2014-3936

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0430%
EPSS Percentile17.34th
Published2014年6月2日
Last Modified2026年5月6日

Vulnerability Description

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

Affected Platforms (CPE)

💻
Dlink

Dir505 Shareport Mobile Companion Firmware

<= 1.07
🔌
Dlink

Dir505 Shareport Mobile Companion

= a1
💻
Dlink

Dir505l Shareport Mobile Companion Firmware

<= 1.01
🔌
Dlink

Dir 505l Shareport Mobile Companion

= a1
💻
Dlink

Dsp W215 Firmware

<= 1.01
🔌
Dlink

Dsp W215

= a1

References & Advisories

関連する脆弱性情報