D Link · D-Link Dir-645 · CVE-2021-43722
**Name of the Vulnerable Software and Affected Versions**
D-Link DIR-645 version 1.03 A1
**Description**
The issue is related to a Buffer Overflow. The `hnap main` function in the cgibin handler uses `sprintf` to format the `soapaction` header onto the stack and has no limit on the size.
**Recommendations**
For D-Link DIR-645 version 1.03 A1, as a temporary workaround, consider restricting access to the cgibin handler until a patch is available. Avoid using the `soapaction` header in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.