Impact
The vulnerability exists in the Authentication Handler component of D‑Link DIR‑868L firmware 2.01b05, where the strcpy function copies user supplied id and password values into a fixed-size buffer. Manipulating these arguments can trigger a stack‑based buffer overflow (CWE‑119) that, due to stack corruption (CWE‑121), may allow an attacker to execute arbitrary code on the device. Because the vulnerable code is invoked when the web authentication page is accessed, the resulting impact is remote code execution, potentially granting full control over the device and any network resources it is connected to.
Affected Systems
The affected product is D‑Link DIR‑868L, firmware revision 2.01b05. No additional vendor or product variants are specified.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score is not available, but the exploit is publicly disclosed and can be performed over the web interface, meaning it can be launched remotely. The vulnerability is not listed in the CISA KEV catalog; however, the combination of a high CVSS score, remote attack vector, and publicly available exploit script raises the likelihood of real‑world exploitation. An attacker could leverage the stack overflow to inject and execute code, leading to full device compromise, data exfiltration, or further network intrusion.
OpenCVE Enrichment