ID

VAR-202405-4042


CVE

CVE-2024-33772


TITLE

D-Link Systems, Inc.  of  DIR-619L  Stack-based buffer overflow vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2024-024091

DESCRIPTION

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime.". D-Link Systems, Inc. The D-Link DIR-619L is a wireless router designed for home and small office environments. It implements the IEEE 802.11n standard and offers a maximum transmission rate of 300Mbps. This vulnerability stems from the failure of the curTime parameter in formTcpipSetup to properly validate the length of input data. An attacker could exploit this vulnerability to cause a denial of service

Trust: 2.16

sources: NVD: CVE-2024-33772 // JVNDB: JVNDB-2024-024091 // CNVD: CNVD-2025-17398

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-17398

AFFECTED PRODUCTS

vendor:dlinkmodel:dir-619lscope:eqversion:2.06b1

Trust: 1.0

vendor:d linkmodel:dir-619lscope: - version: -

Trust: 0.8

vendor:d linkmodel:dir-619lscope:eqversion: -

Trust: 0.8

vendor:d linkmodel:dir-619lscope:eqversion:dir-619l firmware 2.06b1

Trust: 0.8

vendor:d linkmodel:dir-619l rev.b 2.06b1scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-17398 // JVNDB: JVNDB-2024-024091 // NVD: CVE-2024-33772

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-33772
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2024-024091
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2025-17398
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-17398
severity: MEDIUM
baseScore: 5.5
vectorString: AV:A/AC:L/AU:S/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 5.1
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-33772
baseSeverity: MEDIUM
baseScore: 5.7
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 3.6
version: 3.1

Trust: 1.0

OTHER: JVNDB-2024-024091
baseSeverity: MEDIUM
baseScore: 5.7
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-17398 // JVNDB: JVNDB-2024-024091 // NVD: CVE-2024-33772

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

problemtype:Stack-based buffer overflow (CWE-121) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-024091 // NVD: CVE-2024-33772

EXTERNAL IDS

db:NVDid:CVE-2024-33772

Trust: 3.2

db:JVNDBid:JVNDB-2024-024091

Trust: 0.8

db:CNVDid:CNVD-2025-17398

Trust: 0.6

sources: CNVD: CNVD-2025-17398 // JVNDB: JVNDB-2024-024091 // NVD: CVE-2024-33772

REFERENCES

url:https://github.com/yubozhaoo/iot/blob/main/d-link/dir-619l/20240424.md

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2024-33772

Trust: 0.8

sources: CNVD: CNVD-2025-17398 // JVNDB: JVNDB-2024-024091 // NVD: CVE-2024-33772

SOURCES

db:CNVDid:CNVD-2025-17398
db:JVNDBid:JVNDB-2024-024091
db:NVDid:CVE-2024-33772

LAST UPDATE DATE

2025-08-02T23:07:49.874000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-17398date:2025-08-01T00:00:00
db:JVNDBid:JVNDB-2024-024091date:2025-05-22T02:07:00
db:NVDid:CVE-2024-33772date:2025-05-21T14:42:45.587

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-17398date:2025-08-01T00:00:00
db:JVNDBid:JVNDB-2024-024091date:2025-05-22T00:00:00
db:NVDid:CVE-2024-33772date:2024-05-14T15:38:05.437