CVE-2022-41140
published 2023-01-26CVE-2022-41140: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not…
PriorityP185high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.10%
62.1th percentile
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13796.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | multiple_routers | — | — |
| dlink | dir-867_firmware | <= 1.30b08 | — |
| dlink | dir-878_firmware | <= 1.30b06 | — |
| dlink | dir-882-us_firmware | <= 1.30b07 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for network-adjacent unauthenticated HTTP requests to D-Link routers on TCP port 80 targeting the lighttpd service with oversized payloads indicative of stack-based buffer overflow exploitation. ↗
- →GreyNoise released a tag 'D-Link CVE-2022-41140 RCE Attempt' in March 2023, indicating active in-the-wild scanning/exploitation attempts are being observed and can be used for threat hunting. ↗
- ·The vulnerability affects multiple D-Link router models; authentication is not required, meaning any network-adjacent attacker can attempt exploitation without credentials. ↗
- ·Successful exploitation results in code execution as root, indicating full device compromise is possible. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcrm-3jcv-ppvq: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers
ghsa_unreviewed·2023-01-26
CVE-2022-41140 [HIGH] CWE-787 GHSA-qcrm-3jcv-ppvq: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13796.
VulnCheck
D-Link dir-882-us_firmware Stack-based Buffer Overflow
vulncheck·2022·CVSS 8.8
CVE-2022-41140 [HIGH] D-Link dir-882-us_firmware Stack-based Buffer Overflow
D-Link dir-882-us_firmware Stack-based Buffer Overflow
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13796.
Affected: D-Link dir-882-us_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploita
No detection rules found.
No public exploits indexed.
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Debugging D-Link: Emulating firmware and hacking hardware
blogs_greynoiseio·CVSS 8.8
[HIGH] Debugging D-Link: Emulating firmware and hacking hardware
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2023-01-26
Published
Exploited in the wild