Description
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/tools_misc.xgi.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Craig Heffner · pythonremotehardware
https://www.exploit-db.com/exploits/38810
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://pastebin.com/raw.php?i=vbiG42VD
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/248083
Scores
EPSS
0.0293
EPSS Percentile
86.5%
Details
CWE
CWE-119
Status
published
Products (1)
dlink/dir-100
Published
Oct 19, 2013
Tracked Since
Feb 18, 2026