CVE-2016-1558 Information
Feb 14, 2021
cve
Description
Buffer overflow in D-Link DAP-2310 2.06 and earlier DAP-2330 1.06 and earlier DAP-2360 2.06 and earlier DAP-2553 H/W ver. B1 3.05 and earlier DAP-2660 1.11 and earlier DAP-2690 3.15 and earlier DAP-2695 1.16 and earlier DAP-3320 1.00 and earlier and DAP-3662 1.01 and earlier allows remote attackers to have unspecified impact via a crafted ‘dlink_uid’ cookie.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html http://seclists.org/fulldisclosure/2016/Feb/112 http://www.dlink.com/mk/mk/support/support-news/2016/march/16/firmadyne-cve_2016_1558-cve_2016_1559
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: