Lucene search

K
cvelistMitreCVELIST:CVE-2018-10713
HistoryMay 03, 2018 - 4:00 p.m.

CVE-2018-10713

2018-05-0316:00:00
mitre
www.cve.org
5
d-link
dsl-3782 eu
memory corruption
authenticated user
arbitrary code
diagnostics component
buffer overflow

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

48.7%

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a ‘read’ parameter to the ‘/userfs/bin/tcapi’ binary (in the Diagnostics component) using the ‘read <node_name>’ function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

48.7%

Related for CVELIST:CVE-2018-10713