CVE-2019-9125

An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:d-link:dir-878_firmware:1.12b01:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-878:-:*:*:*:*:*:*:*

History

26 Apr 2023, 18:55

Type Values Removed Values Added
First Time Dlink dir-878
Dlink
CPE cpe:2.3:h:d-link:dir-878:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dir-878:-:*:*:*:*:*:*:*

Information

Published : 2019-02-25 05:29

Updated : 2023-12-10 12:44


NVD link : CVE-2019-9125

Mitre link : CVE-2019-9125

CVE.ORG link : CVE-2019-9125


JSON object : View

Products Affected

dlink

  • dir-878

d-link

  • dir-878_firmware
CWE
CWE-306

Missing Authentication for Critical Function

CWE-787

Out-of-bounds Write