CVE-2016-6563

UnknownEPSS 79.95%

Last modified

CVE-2016-6563 is a vulnerability of currently unknown severity. Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. EPSS estimates a 79.95% chance of exploitation in the next 30 days.

Description

Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L, DIR-890L, DIR-885L, DIR-880L, DIR-868L, and DIR-850L.

Metrics

EPSS Probability
79.95%

99.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DlinkDir-823 FirmwareAll versions
DlinkDir-822 FirmwareAll versions
DlinkDir-818l\(W\) FirmwareAll versions
DlinkDir-895l FirmwareAll versions
DlinkDir-890l FirmwareAll versions
DlinkDir-885l FirmwareAll versions
DlinkDir-880l FirmwareAll versions
DlinkDir-868l FirmwareAll versions
DlinkDir-850l FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-6563?
Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L, DIR-890L, DIR-885L, DIR-880L, DIR-868L, and DIR-850L.
How severe is CVE-2016-6563?
Severity scoring for CVE-2016-6563 is pending analysis. The EPSS model estimates a 79.95% probability of exploitation in the next 30 days.
How do I fix CVE-2016-6563?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-6563?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST