D-Link DIR-513 Boa Webserver formSetWanNonLogin sprintf stack-based overflow

CVE Details

Basic Information

Title D-Link DIR-513 Boa Webserver formSetWanNonLogin sprintf stack-based overflow
Type cve
Published 2025-07-20T22:02:05.866Z
Modified 2025-07-20T22:02:05.866Z

Product Information

Vendor D-Link
Product DIR-513
Version 1.10

CVSS Information

Base Score 8.7 (HIGH)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A critical stack-based buffer overflow vulnerability in the Boa Webserver’s formSetWanNonLogin function allows remote attackers to cause a denial of service or execute arbitrary code. The affected product is no longer supported by the vendor.
AI Severity High
AI Vendor D-Link
AI Product Boa Webserver
AI Version 1.10

Affected Products

  • D-Link DIR-513 1.10

Additional Information

CWE List CWE-121, CWE-119
Source VulDB

Description

A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the file /goform/formSetWanNonLogin of the component Boa Webserver. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.