CVE-2022-27631: Critical severity dd-wrt vulnerability
Published Aug 5, 2022
·Updated
A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Affected Software
1 affected component
DD-WRT DD-WRT>=32270<=48599
Event History
Aug 5, 2022
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this memory corruption vulnerability?
The vulnerability ID is CVE-2022-27631.
2
What is the affected software for CVE-2022-27631?
The affected software is DD-WRT, specifically revisions 32270 to 48599.
3
What is the severity of CVE-2022-27631?
The severity of CVE-2022-27631 is critical, with a CVSS score of 9.8.
4
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2022-27631 is CWE-787.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially-crafted HTTP request, which can lead to memory corruption.