CVE-2022-37134: Buffer Overflow
Published Aug 22, 2022
·Updated
D-link DIR-816 A2v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tpusrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tpusrname, resulting in stack overflow.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10cnb04
Dlink DIR-816=a2
Event History
Aug 22, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-37134.
2
What is the severity of CVE-2022-37134?
The severity of CVE-2022-37134 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2022-37134?
The D-link DIR-816 firmware version 1.10cnb04 is affected by CVE-2022-37134.
4
How does the vulnerability in D-link DIR-816 firmware version 1.10cnb04 manifest?
The vulnerability manifests as a buffer overflow when accessing the /goform/form2Wan.cgi endpoint with wantype set to 3, resulting in a stack overflow.
5
Is there a fix available for CVE-2022-37134?
Yes, D-link has released a security bulletin with information on how to address the vulnerability.