CVE-2024-45623

D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

No configuration.

History

03 Sep 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

03 Sep 2024, 12:59

Type Values Removed Values Added
Summary
  • (es) El firmware 1.16RC028 del hardware A de D-Link DAP-2310 permite a atacantes remotos ejecutar código arbitrario a través de un desbordamiento de búfer basado en pila en el binario ATP que maneja solicitudes PHP HTTP GET para el servidor Apache HTTP (httpd). NOTA: Esta vulnerabilidad solo afecta a productos que ya no reciben soporte del fabricante.

02 Sep 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-02 21:15

Updated : 2024-09-03 15:35


NVD link : CVE-2024-45623

Mitre link : CVE-2024-45623

CVE.ORG link : CVE-2024-45623


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')