CVE-2019-9125

An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:d-link:dir-878_firmware:1.12b01:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-878:-:*:*:*:*:*:*:*

History

26 Apr 2023, 18:55

Type Values Removed Values Added
CPE cpe:2.3:h:d-link:dir-878:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dir-878:-:*:*:*:*:*:*:*
First Time Dlink
Dlink dir-878

Information

Published : 2019-02-25 05:29

Updated : 2023-04-26 18:55


NVD link : CVE-2019-9125

Mitre link : CVE-2019-9125


JSON object : View

Products Affected

d-link

  • dir-878_firmware

dlink

  • dir-878
CWE
CWE-787

Out-of-bounds Write

CWE-306

Missing Authentication for Critical Function