D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dap-2310 Firmware
Weaknesses CWE-94
CPEs cpe:2.3:o:d-link:dap-2310_firmware:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dap-2310 Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 02 Sep 2024 20:45:00 +0000

Type Values Removed Values Added
Description D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-03T14:50:09.815Z

Reserved: 2024-09-02T00:00:00

Link: CVE-2024-45623

cve-icon Vulnrichment

Updated: 2024-09-03T14:49:48.824Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-02T21:15:11.363

Modified: 2024-09-03T15:35:15.360

Link: CVE-2024-45623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.