PT-2022-3311 · D Link · D-Link Dir-890L
Published
2022-05-27
·
Updated
2023-08-01
·
CVE-2022-30521
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-890L versions prior to DIR890LA1 FW107b09.bin
Description
The issue is related to a stack-based buffer overflow vulnerability in the LAN-side Web-Configuration Interface of the D-Link Wi-Fi router firmware. This vulnerability is caused by the incorrect checking of string lengths in parameters given by HTTP headers in the
sprintf() function. Exploitation of this issue can allow an attacker to execute arbitrary code by sending a specially constructed payload to port 49152.Recommendations
For versions prior to DIR890LA1 FW107b09.bin, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to port 49152 to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-890L