Buffer Overflow Vulnerability in Netis ADSL Router DL4322D FTP Service
CVE-2018-25125
Key Information:
- Vendor
Netis Systems Co., Ltd.
- Status
- Vendor
- CVE Published:
- 14 November 2025
Badges
What is CVE-2018-25125?
The Netis ADSL Router DL4322D is impacted by a buffer overflow vulnerability in its embedded FTP service. This flaw allows an authenticated remote user to execute malicious FTP commands that pass excessively long arguments, such as the ABOR command. This action leads to a crash or unresponsiveness of the FTP service and, consequently, the router itself, resulting in loss of availability for the device and any users dependent on it. Timely patching and awareness of this vulnerability can help mitigate potential disruptions.
Affected Version(s)
DL4322D 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
