Impact
A remote attack can manipulate PAddress, SubnetMask, or Gateway arguments of the HNAP1 SetStaticRouteSettings API, resulting in a stack-based buffer overflow in the strcpy function. The overflow may allow arbitrary code execution on the router.
Affected Systems
D-Link DIR-823G routers running firmware 1.0.2B05_20181207 are affected. The vulnerability exists in the HNAP1 component on the device.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring network connectivity to the router’s management interface. Based on the description, it is inferred that no special privileges are required beyond remote access to the HNAP1 service.
OpenCVE Enrichment