VYPR
Critical severity9.8NVD Advisory· Published Oct 16, 2023· Updated Jun 17, 2026

CVE-2023-45578

CVE-2023-45578

Description

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the pap_en/chap_en parameter of the pppoe_base.asp function.

Affected products

10
  • cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*
    Range: <=23.08.25d1
  • cpe:2.3:o:dlink:di-7100g\+_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dlink:di-7100g\+_firmware:*:*:*:*:*:*:*:*range: <=23.08.23d1
    • cpe:2.3:o:dlink:di-7100g_firmware:*:*:*:*:*:*:*:*range: <=23.08.23d1
  • cpe:2.3:o:dlink:di-7200g\+_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dlink:di-7200g\+_firmware:*:*:*:*:*:*:*:*range: <=23.08.23d1
    • cpe:2.3:o:dlink:di-7200g_firmware:*:*:*:*:*:*:*:*range: <=23.08.23e1
  • cpe:2.3:o:dlink:di-7300g\+_firmware:*:*:*:*:*:*:*:*
    Range: <=23.08.23d1
  • cpe:2.3:o:dlink:di-7400g\+_firmware:*:*:*:*:*:*:*:*
    Range: <=23.08.23d1
  • Dlink/DI-7003GV2cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=v.23.08.25D1
  • Dlink/DI-7100GV2llm-create
    Range: <=v.23.08.23D1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.