CVE-2018-25125: Netis DL4322D RTK 2.1.1 FTP Service DoS
Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument causes the service, and in practice the router, to crash or become unresponsive, resulting in a loss of availability for the device and connected users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25125?
CVE-2018-25125 has been classified as high severity due to its potential to cause a denial of service through a buffer overflow.
How do I fix CVE-2018-25125?
To fix CVE-2018-25125, update the firmware of the Netis ADSL Router DL4322D to the latest version provided by the manufacturer.
What type of attack can be performed using CVE-2018-25125?
CVE-2018-25125 allows an authenticated remote user to perform a denial of service attack on the FTP service of the router.
Is authentication required to exploit CVE-2018-25125?
Yes, an authenticated user is required to exploit CVE-2018-25125, as the vulnerability is present in the FTP service after logging in.
What devices are affected by CVE-2018-25125?
CVE-2018-25125 affects the Netis ADSL Router DL4322D running specified firmware versions.