CVE-2017-14948

CRITICALCVSS 9.8/10EPSS 4.80%

Last modified

CVE-2017-14948 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. EPSS estimates a 4.80% chance of exploitation in the next 30 days.

Description

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
4.80%

90.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DlinkDir-868l FirmwareAll versions
DlinkDir-890l FirmwareAll versions
DlinkDir-885l FirmwareAll versions
DlinkDir-895l Firmware1.13b03
DlinkDir-880l Firmware1.08b04
DlinkDir-895r Firmware1.13b03

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-14948?
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.
How severe is CVE-2017-14948?
CVE-2017-14948 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 4.80% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14948?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-14948?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST