Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-10021


A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin. A remote unauthenticated attacker can exploit this to execute arbitrary code with root privileges on the device.


Published

2025-07-31T15:15:32.597

Last Modified

2025-09-23T17:45:55.843

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-121

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-605l_firmware ≤ 1.13 Yes
Hardware dlink dir-605l - No

References