Description
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
Problem types
Product status
Timeline
| 2025-11-22: | Advisory disclosed |
| 2025-11-22: | VulDB entry created |
| 2025-11-22: | VulDB entry last update |
Credits
LINXI666 (VulDB User)
References
vuldb.com/?id.333320 (VDB-333320 | D-Link DWR-M920 formPinManageSetup sub_41C7FC buffer overflow)
vuldb.com/?ctiid.333320 (VDB-333320 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.695435 (Submit #695435 | D-Link DWR-M920 v1.1.50 Buffer Overflow)
github.com/QIU-DIE/CVE/issues/45
www.dlink.com/