PT-2022-23492 · D Link · D-Link Dap-1650

Published

2022-09-07

·

Updated

2022-09-09

·

CVE-2022-36588

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DAP1655 is not mentioned, instead DAP1650 version 1.04 is listed, however the correct model is not clear from the description, assuming DAP1650 is correct: D-Link DAP1650 version 1.04
Description The issue is caused by a buffer overflow vulnerability in the fileaccess.cgi program due to the use of strncpy.
Recommendations For D-Link DAP1650 version 1.04, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-36588

Affected Products

D-Link Dap-1650