Rewterz
Multiple D-Link Products Vulnerabilities
October 14, 2024
Rewterz
North Korean APT Kimsuky aka Black Banshee – Active IOCs
October 14, 2024

Multiple D-Link DIR-619L B1 Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-9915 CVSS:8.8

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9914 CVSS:8.8

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9913 CVSS:8.8

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9912 CVSS:8.8

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9911 CVSS:8.8

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9910 CVSS:8.8

A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9909 CVSS:8.8

A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formSetMuti of the file /goform/formSetMuti. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Impact

  • Buffer Overflow

Indicators of Compromise

CVE

  • CVE-2024-9915
  • CVE-2024-9914
  • CVE-2024-9913
  • CVE-2024-9912
  • CVE-2024-9911
  • CVE-2024-9910
  • CVE-2024-9909

Affected Vendors

D-Link

Affected Products

  • D-Link DIR-619L B1 - 2.06

Remediation

Refer to D-Link Website for patch, upgrade, or suggested workaround information.

CVE-2024-9915

CVE-2024-9914

CVE-2024-9913

CVE-2024-9912

CVE-2024-9911

CVE-2024-9910

CVE-2024-9909