D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.4epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Affected products
D-Link · DIR-822Apublic PoCs found — 1
cve_referencetzh00203.notion.site/D-Link-DIR-822A-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80a7af5fdc1af3d5aa73unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.