CVE-2024-57440 Details
Description
D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi
A buffer overflow vulnerability has been identified in the D-Link DSL-3788 router, specifically in hardware revision A1, firmware version 1.01R1B036_EU_EN. The issue arises in the webproc CGI, within the COMM_MAKECustomMsg function of the libssap library. This vulnerability allows for unauthenticated remote code execution, as the function fails to properly validate the length of the input, leading to arbitrary code execution on the device.
Users are advised to update to D-Link DSL-3788 firmware version 1.01R1B037, available on the D-Link support website. After updating, it is important to verify the success of the update by checking the device's software version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dlink dsl-3788 firmware | < 1.01R1B037 |
CPE
Remediation
| |
| dlink dsl-3788 | a1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 20, 2026 | CVE Modified | [email protected] |
| Apr 15, 2025 | Reanalysis | [email protected] |
| Mar 28, 2025 | Initial Analysis | [email protected] |
| Mar 21, 2025 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | New CVE Received | [email protected] |