CVE Details
Basic Information
| Title | D-Link DCS-932L setSystemEmail stack-based overflow |
|---|---|
| Type | cve |
| Published | 2025-06-04T06:00:13.471Z |
| Last Seen |
Product Information
| Vendor | D-Link |
|---|---|
| Product | DCS-932L |
| Version | 2.18.01 |
CVSS Information
| Base Score | 8.7 (HIGH) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical stack-based buffer overflow vulnerability exists in the `setSystemEmail` function of D-Link DCS-932L version 2.18.01. The vulnerability is triggered by manipulating the `EmailSMTPPortNumber` parameter, allowing remote attackers to execute arbitrary code. The product is no longer supported by the vendor. |
|---|---|
| AI Severity | Critical |
| Vendor | D-Link |
| Product | DCS-932L |
| Affected Version | 2.18.01 |
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-121, CWE-119 |
| Bulletin Family | |
| Source Data | D-Link DCS-932L 2.18.01 |
Source Information
| Source Data | D-Link DCS-932L 2.18.01 |
|---|---|
| Source Link |
Description
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail of the file /setSystemEmail. The manipulation of the argument EmailSMTPPortNumber leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score Summary
Base Score: 8.7 (HIGH)