Back to search
CVE-2014-125117
Published: Jul 25, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges.
| Vendor | Product | Versions |
|---|---|---|
D-Link | DSP-W215 | affected 1.02 |
References
https://web.archive.org/web/20140525215526/http://www.devttys0.com/2014/05/hacking-the-dspw215-again/
technical-description
exploit
https://www.vulncheck.com/advisories/dlink-stack-based-buffer-overflow-rce
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now