CVE-2013-6027

Dlink Dir-100 - Memory Corruption

Title source: rule
STIX 2.1

Description

Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/tools_misc.xgi.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Craig Heffner · pythonremotehardware
https://www.exploit-db.com/exploits/38810

References (2)

Core 2
Core References
Exploit x_refsource_misc
http://pastebin.com/raw.php?i=vbiG42VD
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/248083

Scores

EPSS 0.0293
EPSS Percentile 86.5%

Details

CWE
CWE-119
Status published
Products (1)
dlink/dir-100
Published Oct 19, 2013
Tracked Since Feb 18, 2026