CVE-2014-3936

D-Link DSP-W215 <1.01b06 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-3936. PoCs published by Metasploit, Craig Heffner, including Metasploit module exploits/linux/http/dlink_hnap_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in D-Link devices via a malicious HTTP POST request to the HNAP handler, achieving remote code execution. It supports multiple targets and includes automatic fingerprinting for version detection.

Description

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/34064

This Metasploit module exploits a stack-based buffer overflow in D-Link devices via a malicious HTTP POST request to the HNAP handler, achieving remote code execution. It supports multiple targets and includes automatic fingerprinting for version detection.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DIR-505 (v1.06, v1.07), D-Link DSP-W215 (v1.0)
No auth needed
Prerequisites: Network access to the vulnerable device · HNAP service exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Craig Heffner · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_hnap_bof.rb

This Metasploit module exploits a stack-based buffer overflow in D-Link HNAP request handling to achieve remote code execution. It targets specific D-Link devices (DSP-W215, DIR-505) by sending a maliciously crafted HTTP POST request to overflow the stack and redirect execution to a system() call.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DIR-505 (v1.06, v1.07), D-Link DSP-W215 (v1.0)
No auth needed
Prerequisites: Network access to the vulnerable device · HNAP service exposed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58728
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58972
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67651

Scores

EPSS 0.7636
EPSS Percentile 99.5%

Details

CWE
CWE-119
Status published
Products (6)
dlink/dir-505l_shareport_mobile_companion a1
dlink/dir505_shareport_mobile_companion a1
dlink/dir505_shareport_mobile_companion_firmware < 1.07
dlink/dir505l_shareport_mobile_companion_firmware < 1.01
dlink/dsp-w215 a1
dlink/dsp-w215_firmware < 1.01
Published Jun 02, 2014
Tracked Since Feb 18, 2026