CVE-2023-41222
published 2024-05-03CVE-2023-41222: D-Link DIR-3040 prog.cgi SetWan2Settings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers…
PriorityP345medium6.8CVSS 3.1
AVAACLPRHUINSUCHIHAH
EPSS
0.70%
49.0th percentile
D-Link DIR-3040 prog.cgi SetWan2Settings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21622.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-3040 | — | — |
| dlink | dir-3040_firmware | <= 1.20b03 | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.8MEDIUMCVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm4h-65xf-x594: D-Link DIR-3040 prog
ghsa_unreviewed·2024-05-03
CVE-2023-41222 [MEDIUM] CWE-121 GHSA-xm4h-65xf-x594: D-Link DIR-3040 prog
D-Link DIR-3040 prog.cgi SetWan2Settings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability.
The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21622.
Red Hat
kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222
vendor_redhat·2023-03-07·CVSS 7.0
CVE-2023-1476 [HIGH] CWE-416 kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222
kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
Statement: Red Hat Product Security is aware of this issue. Updates will be released as they become available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-03
Published