CVE-2019-10892: D-Link Dir-806 Firmware
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
An issue was discovered in D-Link DIR-806 devices. There is a stack-based buffer overflow in function hnap_main at /htdocs/cgibin. The function will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users. And it finally leads to a stack-based buffer overflow via a special HTTP header.
Affected products
- D-Link Dir-806 Firmware: version 1.0 only
Published 2019-09-06. Last modified 2026-06-17.