Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-30521

Опубликовано: 02 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:dir-890l_firmware:*:*:*:*:*:*:*:*
Версия до 1.07b09 (включая)
cpe:2.3:h:dlink:dir-890l:-:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01758
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

CVSS3: 6.3
fstec
больше 3 лет назад

Уязвимость реализации функции sprintf() микропрограммного обеспечения маршрутизаторов DIR-890L A1, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 82%
0.01758
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-787