VYPR
Unrated severityNVD Advisory· Published Apr 7, 2023· Updated Feb 13, 2025

CVE-2023-24800

CVE-2023-24800

Description

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack overflow in D-Link DIR878 firmware v1.20B05 (sub_495220) allows remote attackers to cause DoS or execute arbitrary code via crafted payload.

Vulnerability

A stack overflow vulnerability exists in the sub_495220 function of D-Link DIR878 firmware version DIR_878_FW120B05. The bug allows an attacker to cause a denial-of-service (DoS) or execute arbitrary code by sending a crafted payload. The exact nature of the input vector is not detailed in available references, but the overflow occurs in a stack buffer within the mentioned function.

Exploitation

An attacker can exploit this vulnerability by supplying a specially crafted payload to the affected device. The exact prerequisites, such as network access or authentication requirements, are not disclosed in the references [1]. However, the vulnerability is remotely exploitable, and no user interaction beyond receiving the payload is required.

Impact

Successful exploitation allows an attacker to cause a denial of service (DoS) or achieve arbitrary code execution on the device. This could lead to full compromise of the router, including potential for remote control, data leakage, or further propagation within the network. The attacker gains the ability to execute code at the device's privilege level.

Mitigation

As of the publication date (April 7, 2023), no official fix has been announced for D-Link DIR878 firmware version DIR_878_FW120B05. Users should monitor D-Link's security bulletin [1] for updates. It is recommended to check if the device is still supported; if it is end-of-life (EOL), consider upgrading to a supported model.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR878description
  • Dlink/DIR878llm-fuzzy
    Range: = FW120B05

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.