CVE-2016-5681 Details
Description
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10063 | CVE | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/332115 | CVE | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/92427 | CVE | Third Party AdvisoryVDB Entry |
| http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10063 | [email protected] | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/332115 | [email protected] | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/92427 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink dir-868l firmware | <= 2.03 <= 3.00 |
CPE
Remediation
| |
| dlink dir-868l | b1 c1 |
CPE
Remediation
| |
| dlink dir-822 firmware | 3.01 |
CPE
Remediation
| |
| dlink dir-822 | a1 |
CPE
Remediation
| |
| d-link dir-880l firmware | <= 1.07 |
CPE
Remediation
| |
| dlink dir-880l | a1 |
CPE
Remediation
| |
| d-link dir-850l firmare | <= 2.07 |
CPE
Remediation
| |
| dlink dir-850l | b1 |
CPE
Remediation
| |
| d-link dir-895l firmware | <= 1.11 |
CPE
Remediation
| |
| dlink dir-895l | a1 |
CPE
Remediation
| |
| d-link dir-817l(w) firmware | <= jul.2016 |
CPE
Remediation
| |
| dlink dir-817l(w) | ax |
CPE
Remediation
| |
| d-link dir-818l(w) firmware | <= 2.05 |
CPE
Remediation
| |
| dlink dir-818l(w) | ax |
CPE
Remediation
| |
| d-link dir-890l firmware | <= 1.09 |
CPE
Remediation
| |
| dlink dir-890l | a1 |
CPE
Remediation
| |
| d-link dir-823 firmware | <= 1.00 |
CPE
Remediation
| |
| dlink dir-823 | a1 |
CPE
Remediation
| |
| d-link dir-885l firmware | <= 1.11 |
CPE
Remediation
| |
| dlink dir-885l | a1 |
CPE
Remediation
| |
Change History
21 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 26, 2023 | Modified Analysis | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2023 | CPE Deprecation Remap | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Aug 26, 2016 | Modified Analysis | [email protected] |
| Aug 26, 2016 | Initial Analysis | [email protected] |