CVE-2022-43619: D-Link DIR-1935 ConfigFileUpload Format String Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of ConfigFileUpload requests to the web management portal. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-16141.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of ConfigFileUpload requests to the web management portal. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-43619?
CVE-2022-43619 is a vulnerability that allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
How severe is CVE-2022-43619?
CVE-2022-43619 has a severity value of 6.8, which is considered medium.
How can an attacker exploit CVE-2022-43619?
To exploit CVE-2022-43619, the attacker needs to bypass the existing authentication mechanism and send a specially crafted request to the affected router.
Does CVE-2022-43619 affect all versions of D-Link DIR-1935 firmware?
No, CVE-2022-43619 only affects D-Link DIR-1935 firmware versions 1.02, 1.03-b1, and 1.03-b2.
How can I mitigate the vulnerability CVE-2022-43619?
To mitigate CVE-2022-43619, it is recommended to update the affected D-Link DIR-1935 router firmware to a non-vulnerable version as provided by the vendor.