Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-9810 | A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges. |
Tue, 23 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dsp-w215 Dlink dsp-w215 Firmware |
|
| CPEs | cpe:2.3:h:dlink:dsp-w215:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dsp-w215_firmware:1.02:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dsp-w215 Dlink dsp-w215 Firmware |
|
| Metrics |
cvssV3_1
|
Sat, 26 Jul 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dsp-w215 |
|
| Vendors & Products |
D-link
D-link dsp-w215 |
Fri, 25 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges. | |
| Title | D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE | |
| Weaknesses | CWE-121 CWE-20 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:03:24.867Z
Reserved: 2025-07-24T20:28:40.816Z
Link: CVE-2014-125117
Updated: 2025-07-25T17:46:22.548Z
Status : Analyzed
Published: 2025-07-25T16:15:26.213
Modified: 2025-09-23T18:03:59.860
Link: CVE-2014-125117
No data.
OpenCVE Enrichment
Updated: 2025-07-26T11:22:07Z
EUVD