CVE-2022-47035: Buffer Overflow
Published Jan 31, 2023
·Updated
Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.
Affected Software
4 affected components
Dlink Dir-825 Firmware<=1.33.0.44ebdd4-embedded
Dlink DIR-825
All of the following
Dlink Dir-825 Firmware<=1.33.0.44ebdd4-embedded
Dlink DIR-825
Remediation
Event History
Jan 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-47035?
CVE-2022-47035 is a buffer overflow vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below.
2
How severe is CVE-2022-47035?
CVE-2022-47035 has a severity rating of 9.8 (Critical).
3
How can an attacker exploit CVE-2022-47035?
An attacker can exploit CVE-2022-47035 by executing arbitrary code via the GetConfig method to the /CPE endpoint.
4
Which software versions are affected by CVE-2022-47035?
D-Link DIR-825 firmware versions up to and including 1.33.0.44ebdd4-embedded are affected.
5
How can I fix CVE-2022-47035?
To fix CVE-2022-47035, update the firmware of your D-Link DIR-825 router to a version that is not vulnerable.