Loading
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a session.cgi?ACTION=logout request involving a long REMOTE_ADDR environment variable.
Use CWE-119, D-Link vendor hub and Dir-629-B Firmware product page to widen CVE-2018-10996 into its surrounding weakness, vendor, and product context.