CVE-2024-42812 is a critical buffer overflow vulnerability affecting D-Link DIR-860L v2.03 routers, stemming from insufficient length validation for the SID field in gena.cgi. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to remotely crash the device or execute arbitrary commands with low attack complexity. Although there is no evidence of active exploitation, public exploit code, or significant community discussion, the high EPSS and FAUCET Risk Score indicate a substantial potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.3CPE matchmatch criteria | cpe:2.3:o:dlink:dir-860l_firmware:2.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.