Buffer Overflow Vulnerability in D-Link DIR-645 Router
CVE-2021-43722
9.8CRITICAL
Summary
The D-Link DIR-645 1.03 A1 router is identified as having a buffer overflow vulnerability. This occurs in the hnap_main function within the cgibin handler, where the sprintf function is employed to format the soapaction header onto the stack without imposing any constraints on its size. This lack of size limitation allows for the potential overwriting of memory, which could be exploited by attackers to execute arbitrary code or disrupt router operations. Users are advised to assess their devices and apply appropriate firmware updates to mitigate associated risks.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved