Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37134


D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.


Published

2022-08-22T15:15:16.870

Last Modified

2024-11-21T07:14:30.113

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-1284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-816_firmware 1.10cnb04 Yes
Hardware dlink dir-816 a2 No

References