peter bassill · operator
$ cve CVE-2014-3936 JSON

CVE-2014-3936 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 76.6% (pctl 100)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS76.56% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2014-06-02
Last modified2026-06-17

Affected (6)

VendorProduct
dlinkdir-505l shareport mobile companion
dlinkdir505 shareport mobile companion
dlinkdir505 shareport mobile companion firmware
dlinkdir505l shareport mobile companion firmware
dlinkdsp-w215
dlinkdsp-w215 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD