Buffer Overflow Vulnerability in D-Link DIR-645 Router
CVE-2021-43722

9.8CRITICAL

Key Information:

Vendor
D-Link
Vendor
CVE Published:
31 March 2022

Summary

The D-Link DIR-645 1.03 A1 router is identified as having a buffer overflow vulnerability. This occurs in the hnap_main function within the cgibin handler, where the sprintf function is employed to format the soapaction header onto the stack without imposing any constraints on its size. This lack of size limitation allows for the potential overwriting of memory, which could be exploited by attackers to execute arbitrary code or disrupt router operations. Users are advised to assess their devices and apply appropriate firmware updates to mitigate associated risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.