PT-2025-7522 · D Link · D-Link Dap-1320

Hand_King

·

Published

2025-02-21

·

Updated

2025-02-26

·

CVE-2025-1538

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DAP-1320 version 1.00
Description A critical vulnerability was found in the function set ws action of the file /dws/api/. The manipulation leads to a heap-based buffer overflow. The attack can be launched remotely. This issue only affects products that are no longer supported by the maintainer.
Recommendations For D-Link DAP-1320 version 1.00, as a temporary workaround, consider disabling the set ws action function until a patch is available. However, since the product is no longer supported, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-01990
CVE-2025-1538

Affected Products

D-Link Dap-1320