CVE-2018-8941

HIGH

D-link Dsl-3782 Firmware - Memory Corruption

Title source: rule
STIX 2.1

Description

Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.

Exploits (1)

nomisec WORKING POC 9 stars
by SECFORCE · poc
https://github.com/SECFORCE/CVE-2018-8941

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/SECFORCE/CVE-2018-8941

Scores

CVSS v3 8.8
EPSS 0.2296
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
d-link/dsl-3782_firmware 1.01
Published Apr 03, 2018
Tracked Since Feb 18, 2026