QID 731251
Date Published: 2024-03-14
QID 731251: D-Link DIR-822 Buffer Overflow Vulnerability
A stack-based buffer overflow vulnerability is discovered in the (Home Network Administration Protocol) service on the D-Link DIR-822 routers. This vulnerability can be exploited by unauthenticated attackers to gain arbitrary remote code execution on the vulnerable router.
Note: D-Link DIR-822 routers are End Of Life and no patches will be released for the vulnerability.
QID Detection Logic (Unauthenticated):
This QID sends an HTTP GET request to check for D-Link DIR-822 Router.
Successful exploitation of the vulnerability may allow unauthenticated attackers to take full control of affected routers, potentially stealing sensitive data, disrupting your internet connection, or using your device for malicious activities.
Solution
The DIR-822, all models of A and B hardware revisions, have reached their End of Life ("EOL"). Customers are advised to switch to different router models. For more information, please refer to the D-Link Security Advisory
Vendor References
- D-Link Security Advisory -
supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10372
CVEs related to QID 731251
Software Advisories
| Advisory ID | Software | Component | Link |
|---|