PT-2022-7101 · D Link · D-Link Dir-878+1

Wolin Zhuang

+1

·

Published

2022-12-23

·

Updated

2023-03-03

·

CVE-2022-46566

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-882 version DIR882A1 FW130B06 D-Link DIR-878 version DIR 878 FW1.30B08
Description A stack overflow issue was discovered in the SetQuickVPNSettings module of the D-Link DIR-882 and DIR-878 wireless routers, related to the Password parameter. This issue can be exploited by a remote attacker to execute arbitrary code.
Recommendations For D-Link DIR-882 version DIR882A1 FW130B06, consider disabling the SetQuickVPNSettings module until a patch is available. For D-Link DIR-878 version DIR 878 FW1.30B08, restrict access to the SetQuickVPNSettings module to minimize the risk of exploitation. Avoid using the Password parameter in the affected module until the issue is resolved.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-07584
CVE-2022-46566

Affected Products

D-Link Dir-878
D-Link Dir-882