Cyber Resilience

CVE-2024-33772

MediumPublic PoC

Published: 14 May 2024

Published
14 May 2024
Modified
21 May 2025
KEV Added
Patch
CVSS Score v3.1 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0070 72.5th percentile
Risk Priority 12 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-33772 is a medium-severity Stack-based Buffer Overflow (CWE-121) vulnerability in Dlink Dir-619L Firmware. Its CVSS base score is 5.7 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked in the top 27.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

Buffer overflow in Boa web server allows remote authenticated users to crash the service via crafted 'curTime' parameter, enabling application exploitation for endpoint denial of service.

Affected Assets

dlink
dir-619l firmware
2.06b1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References