Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Polaris

#24422of 53,632
9.8Total CVSS
Vulnerabilities · 1
PT-2022-11894
9.8
2022-03-31
D Link · D-Link Dir-645 · CVE-2021-43722
**Name of the Vulnerable Software and Affected Versions** D-Link DIR-645 version 1.03 A1 **Description** The issue is related to a Buffer Overflow. The `hnap main` function in the cgibin handler uses `sprintf` to format the `soapaction` header onto the stack and has no limit on the size. **Recommendations** For D-Link DIR-645 version 1.03 A1, as a temporary workaround, consider restricting access to the cgibin handler until a patch is available. Avoid using the `soapaction` header in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.