First published: Thu Mar 31 2022(Updated: )
D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-645 Firmware | =1.03 | |
Dlink Dir-645 | =a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this D-Link DIR-645 issue is CVE-2021-43722.
The severity of CVE-2021-43722 is critical with a CVSS score of 9.8.
The affected software version of CVE-2021-43722 is D-Link DIR-645 Firmware 1.03 A1.
The vulnerability in D-Link DIR-645 occurs due to a buffer overflow in the hnap_main function.
Yes, it is recommended to update to a fixed version of the firmware provided by D-Link to mitigate the vulnerability.