CVE-2022-29327
CVE-2022-29327 Vulnerability Analysis & Exploit Intelligence
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.
Published Updated Sources: cvelistV5, mitre
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
4%
chance of exploitation in 30 days
Affects
Not published
no source named an affected product
CVSS base
Unscored
no source published a base score
Detection
Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.
- Search application, proxy, and WAF logs for requests touching /goform/websURLFilterAddDel.
References
2 on the record
- www.dlink.com/en/security-bulletin/
x_refsource_MISC
- github.com/EPhaha/IOT_vuln/tree/main/d-link/dir-816/9
x_refsource_MISC
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.