An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code via a POST to ntp_sync.cgi with a sufficiently long parameter ntp_server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-07T00:30:13
Updated: 2024-08-04T10:58:40.116Z
Reserved: 2020-03-07T00:00:00
Link: CVE-2020-10214
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-07T01:15:15.190
Modified: 2024-11-21T04:54:58.843
Link: CVE-2020-10214
Redhat
No data.