CVE-2024-45623
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
02/09/2024
Last modified:
03/09/2024
Description
D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



