CVE-2022-41140: D-Link Multiple Routers lighttpd Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this D-Link vulnerability?
The vulnerability ID for this D-Link vulnerability is CVE-2022-41140.
What is the severity of CVE-2022-41140?
The severity of CVE-2022-41140 is high with a CVSS score of 8.8.
Which software is affected by CVE-2022-41140?
Multiple D-Link routers are affected by CVE-2022-41140, including the DIR-882-US, DIR-867, and DIR-878 models.
Is authentication required to exploit CVE-2022-41140?
No, authentication is not required to exploit CVE-2022-41140.
How can I fix CVE-2022-41140?
To fix CVE-2022-41140, it is recommended to update to the latest firmware provided by D-Link and follow the instructions provided in their security announcement.