Impact
The vulnerability is an out‑of‑bounds write in the Multipart Handler within /load_file.cgi of D‑Link DSM‑G600 firmware 1.01. A crafted multipart request can corrupt a buffer by writing beyond its allocated bounds, potentially leading to remote code execution or other unintended behavior. The weakness is classified as CWE‑119 and CWE‑787.
Affected Systems
Only the D‑Link DSM‑G600 router is affected. The firmware version identified as vulnerable is 1.01; other builds may also be impacted, but specific versions are not listed in the CNA data. The flaw exists in the HTTP multipart file‑upload handler and can be triggered remotely by sending a malformed request.
Risk and Exploitability
The CVSS score of 8.7 indicates a high risk of impact, and the publicly available exploit demonstrates a high likelihood of real‑world usage. The exploit can be launched from any network location that can reach the router’s HTTP interface, meaning that the attack vector is remote. Although EPSS data is not available and the issue is not yet listed in CISA’s KEV catalog, the combination of a high CVSS score and open publication points to a significant risk to exposed routers.
OpenCVE Enrichment