8.8
CVSSv3

CVE-2024-57376

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: NA | VMScore: 980 | EPSS: 0.00105 | KEV: Not Included
Published: 28/01/2025 Updated: 29/01/2025

Vulnerability Summary

Buffer Overflow in D-Link DSR Series Routers Enables Unauthenticated Remote Code Execution

A buffer overflow vulnerability exists in D-Link DSR router series including models DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, and DSR-1000N within firmware versions 3.13 to 3.17B901C. This security flaw enables unauthenticated users to perform remote code execution on the affected devices, potentially compromising network security and allowing unauthorized system access.

Vulnerability Trend

Github Repositories

CVE-2024-57376 exploit

CVE-2024-57376 Pre-auth remote code execution exploit for D-Link DSR-250 and DSR-250N Security advisory: supportannouncementusdlinkcom/security/publicationaspx?name=SAP10415 Usage $ python3 exploitpy usage: <host> <port> <command> Example $ python3 exploitpy 19216811 443 id [+]