Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-37134

Опубликовано: 22 авг. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:dir-816_firmware:1.10cnb04:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-816:a2:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01856
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1284

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

EPSS

Процентиль: 83%
0.01856
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1284