CVE-2024-44674: D-Link Covr-2600r Firmware

Medium severity, CVSS 5.7. EPSS: 4.2% chance of exploitation in the next 30 days.

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

Affected products

  • D-Link Covr-2600r Firmware: version 1.01b05 only

Published 2024-10-07. Last modified 2026-06-17.