CVE-2023-27720
Description
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
D-Link DIR878 firmware 1.30B08 has a stack overflow in sub_48d630, allowing DoS or RCE via a crafted payload.
Vulnerability
A stack-based buffer overflow vulnerability exists in the sub_48d630 function of D-Link DIR878 firmware version 1.30B08 [1]. The function reads a user-provided parameter without any length check, leading to a stack-based buffer overflow when the input exceeds the buffer size [1]. This affects the firmware as available from the vendor's download site for revision A [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request to the affected device, supplying overly long data to the parameter processed by sub_48d630 [1]. No authentication is required, making the vulnerability remotely exploitable over the network [1]. The vendor advisory does not provide detailed exploit steps, but the researcher notes that a proof-of-concept could be developed [1].
Impact
Successful exploitation allows an attacker to cause a denial of service (DoS) by crashing the device, or to execute arbitrary code on the router with root privileges, leading to full device compromise [1].
Mitigation
D-Link's security bulletin page does not list a specific patch for this vulnerability at the time of publication [2]. Users should monitor the vendor's security advisory page for a firmware update. As the device may be approaching end-of-life, users should consider replacing the router if no patch becomes available [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/DIR878description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.