Title : D-Link Routers UPnP "M-SEARCH" Request Handling Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-2829 CVE ID : CVE-2006-3687
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-17
Technical Description
A vulnerability has been identified in various D-Link routers, which could be exploited by remote attackers to take complete control of an affected device. This flaw is due to a stack overflow error in the UPnP (Universal Plug and Play) service when handling an overly long "M-SEARCH" request (port 1900/UDP), which could be exploited by remote attackers to execute arbitrary commands.