References https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html https://nvd.nist.gov/vuln/detail/CVE-2024-45694 https://zeropath.com/blog/cve-2025-13305-dlink-router-buffer-overflow-summary https://zeropath.com/blog/cve-2025-13304-dlink-buffer-overflow-summary https://github.com/LonTan0/CVE/blob/main/Stack-Based%20Buffer%20Overflow%20Vulnerability%20in%20hedwig.cgi%20of%20D-Link%20DIR-600.md https://nvd.nist.gov/vuln/detail/CVE-2024-45695 https://www.exploit-db.com/exploits/52469 https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10341 https://0xfatty.github.io/research/2020/02/13/cve-2020-8962-d-link-dir-842-stack-based-buffer-overflow.html https://0x3f97.github.io/exploit/2018/05/13/D-Link-DIR-816-A2-CN-router-stack-based-buffer-overflow/
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionWordPress WebStack主题 /wp-admin/admin-ajax.php 文件上传漏洞(CVE-2026-1555)CentreStack 本地文件包含漏洞(CVE-2025-11371)全程云 /OA/api/2.0/HR/EntryApply/GetBaseData SQL 注入漏洞Apache CloudStack /client/api/ 默认口令漏洞Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)PoCCVE-2025-62613: VDO.Ninja - DOM-Based Cross-Site ScriptingPoCservicestack-requestlogs: ServiceStack Request Logs - Unauthenticated AccessPoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials(CVE-2025-14611)Gladinet CentreStack和Triofox AES加密硬编码漏洞导致任意文件包含及安全降级易达科技-ECMS getProjectBaseDocData SQL注入漏洞PoC易达科技-ECMS getProjectBaseDocData 存在SQL注入漏洞