peter bassill · operator
$ cve CVE-2016-1558 JSON

CVE-2016-1558

9.8
CRITICAL · CVSS 3.0 · EPSS 9.1% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, and DAP-3662 1.01 and earlier allows remote attackers to have unspecified impact via a crafted 'dlink_uid' cookie.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.1% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2017-04-21
Last modified2026-06-17

Affected (20)

VendorProduct
dlinkdap-2230
dlinkdap-2230 firmware
dlinkdap-2310
dlinkdap-2310 firmware
dlinkdap-2330
dlinkdap-2330 firmware
dlinkdap-2360
dlinkdap-2360 firmware
dlinkdap-2553
dlinkdap-2553 firmware
dlinkdap-2660
dlinkdap-2660 firmware
dlinkdap-2690
dlinkdap-2690 firmware
dlinkdap-2695
dlinkdap-2695 firmware
dlinkdap-3320
dlinkdap-3320 firmware
dlinkdap-3662
dlinkdap-3662 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD