PT-2022-18358 · D Link · D-Link Dir-619 Ax
Skyvast404
·
Published
2022-04-10
·
Updated
2022-04-19
·
CVE-2022-27289
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-619 Ax version 1.00
Description
A stack overflow was discovered in the function formSetWanL2TP, allowing attackers to cause a Denial of Service (DoS) via the
curTime parameter.Recommendations
For D-Link DIR-619 Ax version 1.00, as a temporary workaround, consider disabling the formSetWanL2TP function until a patch is available. Restrict access to the
curTime parameter in the affected API endpoint to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-619 Ax