216.73.216.233

CVE-2012-10021

· Published 31/07/2025 15:15 · Modified 31/07/2025 18:42

Labels: CVE-2012-10021 2025-07-31CVE-2012-10021CWE-121[email protected]

Essential information

Published
31/07/2025 15:15
Modified
31/07/2025 18:42
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin. A remote unauthenticated attacker can exploit this to execute arbitrary code with root privileges on the device.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
d-link / dir-605l wireless n300 cloud router cpe:2.3:a:d-link:dir-605l_wireless_n300_cloud_router:1.12-1.13:*:*:*:*:*:*:*

References