← Voltar para CVEs
CVE-2022-30521
CRITICAL9.8
Descricao
The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado6/2/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
dlink:dir-890ldlink:dir-890l_firmware
Fraquezas (CWE)
CWE-787
Referencias
https://github.com/winmt/CVE/blob/main/DIR-890L/README.md(cve@mitre.org)
https://github.com/winmt/my-vuls/tree/main/DIR-890L(cve@mitre.org)
https://www.dlink.com/en/security-bulletin/(cve@mitre.org)
https://github.com/winmt/CVE/blob/main/DIR-890L/README.md(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/winmt/my-vuls/tree/main/DIR-890L(af854a3a-2127-422b-91ae-364da2661108)
https://www.dlink.com/en/security-bulletin/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.