CVE-2023-45576 Details
Description
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the remove_ext_proto/remove_ext_port parameter of the upnp_ctrl.asp function.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 17, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Archerber/bug_submit/blob/main/D-Link/DI-7xxxx/bug3.md | CVE | ExploitThird Party Advisory |
| https://github.com/Archerber/bug_submit/blob/main/D-Link/DI-7xxxx/bug3.md | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink di-7003g firmware | <= 23.08.25d1 |
CPE
Remediation
| |
| dlink di-7003g | v2.d1 |
CPE
Remediation
| |
| dlink di-7100g+ firmware | <= 23.08.23d1 |
CPE
Remediation
| |
| dlink di-7100g+ | v2.d1 |
CPE
Remediation
| |
| dlink di-7100g firmware | <= 23.08.23d1 |
CPE
Remediation
| |
| dlink di-7100g | v2.d1 |
CPE
Remediation
| |
| dlink di-7200g+ firmware | <= 23.08.23d1 |
CPE
Remediation
| |
| dlink di-7200g+ | v2.d1 |
CPE
Remediation
| |
| dlink di-7200g firmware | <= 23.08.23e1 |
CPE
Remediation
| |
| dlink di-7200g | v2.e1 |
CPE
Remediation
| |
| dlink di-7300g+ firmware | <= 23.08.23d1 |
CPE
Remediation
| |
| dlink di-7300g+ | v2.d1 |
CPE
Remediation
| |
| dlink di-7400g+ firmware | <= 23.08.23d1 |
CPE
Remediation
| |
| dlink di-7400g+ | v2.d1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 19, 2023 | Initial Analysis | [email protected] |
| Oct 18, 2023 | CVE Modified | [email protected] |