VYPR
Critical severity9.8NVD Advisory· Published Jul 25, 2025· Updated Jun 17, 2026

CVE-2014-125117

CVE-2014-125117

Description

A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Dlink/Dsp W2153 versions
    cpe:2.3:o:dlink:dsp-w215_firmware:1.02:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:dlink:dsp-w215_firmware:1.02:*:*:*:*:*:*:*
    • (no CPE)range: 1.02
    • (no CPE)range: 1.02
  • Dlink/my_cgi.cgillm-create
    Range: 1.02

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.