CVE-2025-1538: D-Link DAP-1320 api set_ws_action heap-based overflow
Published Feb 21, 2025
·Updated
A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function setwsaction of the file /dws/api/. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
3 affected components
All of the following
Dlink Dap-1320 Firmware=1.0
Dlink Dap-1320
D-Link DAP-1320
Event History
Feb 21, 2025
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1538?
CVE-2025-1538 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-1538?
CVE-2025-1538 is a heap-based buffer overflow vulnerability.
3
Can CVE-2025-1538 be exploited remotely?
Yes, CVE-2025-1538 can be exploited remotely by attackers.
4
Which device is affected by CVE-2025-1538?
CVE-2025-1538 affects the D-Link DAP-1320 device.
5
How can I mitigate CVE-2025-1538?
Mitigation for CVE-2025-1538 should involve applying any available firmware updates from D-Link.