CVE-2016-1558

high-risk
Published 2017-04-21

Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, and DAP-3662 1.01 and earlier allows remote attackers to have unspecified impact via a crafted 'dlink_uid' cookie.

Do I need to act?

!
14.9% chance of exploitation in next 30 days
EPSS score — higher than 85% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (10)

Dap-3662 Firmware
Dap-2310 Firmware
Dap-2330 Firmware
Dap-2360 Firmware
Dap-2553 Firmware
Dap-3320 Firmware
Dap-2690 Firmware
Dap-2695 Firmware

Affected Vendors

60
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 12/34 · Low
Exposure 16/34 · Moderate