CVE-2021-43722

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
31/03/2022
Last modified:
08/04/2022

Description

D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-645_firmware:1.03:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-645:a1:*:*:*:*:*:*:*