CVE-2022-41140 is a critical stack-based buffer overflow vulnerability affecting multiple D-Link router models, including the DIR-867, DIR-878, and DIR-882. This flaw, residing in the lighttpd service on TCP port 80, allows unauthenticated, network-adjacent attackers to execute arbitrary code with root privileges due to insufficient validation of user-supplied data length. With a CVSS score of 8.8 (High), it presents a significant risk as it requires no authentication and has low attack complexity. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, and community discussion is minimal, the potential for full system compromise by an attacker on the same network is high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.30b07CPE matchmatch criteria | cpe:2.3:o:dlink:dir-882-us_firmware:*:*:*:*:*:*:*:* | ||
<= 1.30b08CPE matchmatch criteria | cpe:2.3:o:dlink:dir-867_firmware:*:*:*:*:*:*:*:* | ||
<= 1.30b06CPE matchmatch criteria | cpe:2.3:o:dlink:dir-878_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.