← Vulnerability feed

Vulnerability record · CVE-2002-1865 · published 31 December 2002

CVE-2002-1865: D-link di-804 vulnerability

D Link · Di 804

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

5.0 CVSS 2.0 Medium EPSS 2.9% · top 13.6%
5.0CVSS 2.0 base score
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1865 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2005-4257Linksys befw11s4 vulnerabilityLinksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destinatio…EPSS 1.4%7.5CVE-2001-0514Atmel 802.11b vnet-b access point vulnerabilitySNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings wi…EPSS 1.6%5.0CVE-2002-2137Alloy gl-2422ap-s vulnerabilityGlobalSunTech Wireless Access Points (1) WISECOM GL2422AP-0T, and possibly OEM products such as (2) D-Link DWL-900AP+ B1 2.1 and 2.2, (3) ALLOY GL-24…EPSS 1.5%5.0CVE-2002-1312Linksys befn2ps4 vulnerabilityBuffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable…EPSS 2.0%5.0CVE-2002-1069D-link di-804 vulnerabilityThe remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or…EPSS 1.9%5.0CVE-2001-0888Atmel firmware vulnerabilityAtmel Firmware 1.3 Wireless Access Point (WAP) allows remote attackers to cause a denial of service via a SNMP request with (1) a community string ot…EPSS 2.4%5.0CVE-2001-1137D-link dl-704 vulnerabilityD-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram …EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2002-1865), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.