Vulnerability Description
Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to UDP port 1900.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| D-Link | Di-604 Broadband Router | All versions |
| D-Link | Di-784 | All versions |
| D-Link | Ebr-2310 Ethernet Broadband Router | All versions |
| D-Link | Wbr-1310 Wireless G Router | All versions |
| D-Link | Wbr-2310 Rangebooster G Router | All versions |
| Dlink | Di-524 | All versions |
| Dlink | Di-624 | All versions |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0363.html
- http://secunia.com/advisories/21081Vendor Advisory
- http://securitytracker.com/id?1016511
- http://www.eeye.com/html/research/advisories/AD20060714.html
- http://www.kb.cert.org/vuls/id/971705US Government Resource
- http://www.osvdb.org/27333
- http://www.securityfocus.com/archive/1/440298/100/0/threaded
- http://www.securityfocus.com/archive/1/440852/100/100/threaded
- http://www.securityfocus.com/bid/19006
- http://www.vupen.com/english/advisories/2006/2829
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27755
- http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0363.html
- http://secunia.com/advisories/21081Vendor Advisory
- http://securitytracker.com/id?1016511
- http://www.eeye.com/html/research/advisories/AD20060714.html
FAQ
What is CVE-2006-3687?
CVE-2006-3687 is a vulnerability with a CVSS score of 7.5 (HIGH). Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, ...
How severe is CVE-2006-3687?
CVE-2006-3687 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3687?
Check the references section above for vendor advisories and patch information. Affected products include: D-Link Di-604 Broadband Router, D-Link Di-784, D-Link Ebr-2310 Ethernet Broadband Router, D-Link Wbr-1310 Wireless G Router, D-Link Wbr-2310 Rangebooster G Router.