CVE-2024-44674

Severity CVSS v4.0:
Pending analysis
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
07/10/2024
Last modified:
21/05/2025

Description

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:covr-2600r_firmware:1.01b05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:covr-2600r:-:*:*:*:*:*:*:*