PT-2022-19546 · D Link · D-Link Dap-1330

Published

2022-05-10

·

Updated

2022-05-16

·

CVE-2022-29329

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DAP-1330 OSS-firmware version 1.00b21
Description A heap overflow issue was discovered via the devicename parameter in the "/goform/setDeviceSettings" API endpoint.
Recommendations For D-Link DAP-1330 OSS-firmware version 1.00b21, as a temporary workaround, consider restricting access to the "/goform/setDeviceSettings" API endpoint to minimize the risk of exploitation. Avoid using the devicename parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29329

Affected Products

D-Link Dap-1330