Description

D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of D-Link DIR-3040 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the prog.cgi program, which handles HNAP requests made to the lighttpd webserver listening on ports 80 and 443. The issue results from the lack of proper memory management when processing HTTP cookie values. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. . Was ZDI-CAN-21668.

INFO

Published Date :

2024-05-23T21:29:48.169Z

Last Modified :

2024-08-01T21:11:12.440Z

Source :

zdi
AFFECTED PRODUCTS

The following products are affected by CVE-2024-5294 vulnerability.

Vendors Products
D-link
  • Dir-3040
Dlink
  • Dir-3040
  • Dir-3040 Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-5294.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact