CVE-2017-8412 is a critical stack overflow vulnerability affecting D-Link DCS-1100 and DCS-1130 devices. The vulnerability arises from a lack of bounds checking when the mp4ts binary logs HTTP VERB values, allowing an attacker to overwrite the program counter (PC) register. This flaw has a CVSS score of 8.8 (HIGH), indicating it can be exploited over the network with low complexity and no user interaction, leading to high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, and community discussion is minimal, the potential for remote code execution or command injection remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dcs-1130_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dcs-1100_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.