D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-08-22T14:41:44

Updated: 2024-08-03T10:21:33.147Z

Reserved: 2022-08-01T00:00:00

Link: CVE-2022-37134

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-22T15:15:16.870

Modified: 2023-08-08T14:21:49.707

Link: CVE-2022-37134

cve-icon Redhat

No data.