CVE-2016-6563
CRITICAL EXPLOITEDD-Link DIR Routers - Stack-Based Buffer Overflow via Malformed SOAP HNAP Login Action
Title source: llmExploitation Summary
CVE-2016-6563 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Metasploit, Pedro Ribeiro <[email protected]>, including a Metasploit module exploits/linux/http/dlink_hnap_login_bof.
AI-analyzed exploit summary This Metasploit module exploits a pre-authentication stack buffer overflow in D-Link routers via the HNAP SOAP protocol, allowing remote code execution on both MIPS and ARM architectures.
Description
Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L, DIR-890L, DIR-885L, DIR-880L, DIR-868L, and DIR-850L.
Exploits (2)
This Metasploit module exploits a pre-authentication stack buffer overflow in D-Link routers via the HNAP SOAP protocol, allowing remote code execution on both MIPS and ARM architectures.
This Metasploit module exploits a pre-authentication stack buffer overflow in D-Link routers via the HNAP SOAP protocol. It supports both MIPS and ARM architectures, leveraging ROP gadgets to achieve remote code execution.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H