VYPR
Unrated severityNVD Advisory· Published Apr 9, 2023· Updated Feb 12, 2025

CVE-2023-27720

CVE-2023-27720

Description

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR878 firmware 1.30B08 has a stack overflow in sub_48d630, allowing DoS or RCE via a crafted payload.

Vulnerability

A stack-based buffer overflow vulnerability exists in the sub_48d630 function of D-Link DIR878 firmware version 1.30B08 [1]. The function reads a user-provided parameter without any length check, leading to a stack-based buffer overflow when the input exceeds the buffer size [1]. This affects the firmware as available from the vendor's download site for revision A [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the affected device, supplying overly long data to the parameter processed by sub_48d630 [1]. No authentication is required, making the vulnerability remotely exploitable over the network [1]. The vendor advisory does not provide detailed exploit steps, but the researcher notes that a proof-of-concept could be developed [1].

Impact

Successful exploitation allows an attacker to cause a denial of service (DoS) by crashing the device, or to execute arbitrary code on the router with root privileges, leading to full device compromise [1].

Mitigation

D-Link's security bulletin page does not list a specific patch for this vulnerability at the time of publication [2]. Users should monitor the vendor's security advisory page for a firmware update. As the device may be approaching end-of-life, users should consider replacing the router if no patch becomes available [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR878description
  • Dlink/DIR878llm-fuzzy
    Range: =1.30B08

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.