CVE-2012-10021 Details
Description
A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin. A remote unauthenticated attacker can exploit this to execute arbitrary code with root privileges on the device.
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-605L Wireless N300 Cloud Router. This vulnerability is present in firmware versions 1.12 and 1.13. The issue arises in the Boa Web server while processing user-supplied CAPTCHA data through the FILECODE parameter in the formLogin endpoint. The vulnerability is caused by the unsafe use of sprintf(), which allows a remote, unauthenticated attacker to execute arbitrary code with root privileges on the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink dir-605l firmware | >= 1.12, <= 1.13 |
CPE
Remediation
| |
| dlink dir-605l | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Jul 31, 2025 | New CVE Received | [email protected] |