ZDI-CAN-21622: ZDI-23-1330: D-Link DIR-3040 prog.cgi SetWan2Settings Stack-Based Buffer Overflow Remote Code Execution Vulnerability
Published Sep 7, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
D-Link DIR-3040
Event History
Sep 7, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 2, 2025
Advisory Published
via ZDI·02:05 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21622?
ZDI-CAN-21622 has a high severity rating due to its potential to allow arbitrary code execution by network-adjacent attackers.
2
How do I fix ZDI-CAN-21622?
To mitigate ZDI-CAN-21622, update the D-Link DIR-3040 router with the latest firmware provided by D-Link.
3
Who is affected by ZDI-CAN-21622?
ZDI-CAN-21622 affects installations of D-Link DIR-3040 routers that have not been updated.
4
Is authentication required to exploit ZDI-CAN-21622?
Yes, authentication is required for an attacker to exploit the ZDI-CAN-21622 vulnerability.
5
What should I do if I am using a D-Link DIR-3040 affected by ZDI-CAN-21622?
If you are using a D-Link DIR-3040, you should apply the security patch released by D-Link immediately to protect against ZDI-CAN-21622.