cbcvebase.
CVE-2022-41140
published 2023-01-26

CVE-2022-41140: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not…

PriorityP185high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.10%
62.1th percentile
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13796.

Affected

4 ranges
VendorProductVersion rangeFixed in
d-linkmultiple_routers
dlinkdir-867_firmware<= 1.30b08
dlinkdir-878_firmware<= 1.30b06
dlinkdir-882-us_firmware<= 1.30b07

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for network-adjacent unauthenticated HTTP requests to D-Link routers on TCP port 80 targeting the lighttpd service with oversized payloads indicative of stack-based buffer overflow exploitation.
  • GreyNoise released a tag 'D-Link CVE-2022-41140 RCE Attempt' in March 2023, indicating active in-the-wild scanning/exploitation attempts are being observed and can be used for threat hunting.
  • ·The vulnerability affects multiple D-Link router models; authentication is not required, meaning any network-adjacent attacker can attempt exploitation without credentials.
  • ·Successful exploitation results in code execution as root, indicating full device compromise is possible.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.