CVE-2022-43632 – D-Link DIR-1935 SetQoSSettings QoSInfo Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-43632
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetQoSSettings requests to the web management portal. When parsing subelements within the QoSInfo element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. • https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310 https://www.zerodayinitiative.com/advisories/ZDI-22-1504 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-43623 – D-Link DIR-1935 SetWebFilterSetting WebFilterURLs Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-43623
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of SetWebFilterSetting requests to the web management portal. When parsing the WebFilterURLs element, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. • https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310 https://www.zerodayinitiative.com/advisories/ZDI-22-1492 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2022-43621 – D-Link DIR-1935 HNAP Incorrect Comparison Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2022-43621
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented comparison. An attacker can leverage this vulnerability to bypass authentication on the system. • https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310 https://www.zerodayinitiative.com/advisories/ZDI-22-1503 • CWE-697: Incorrect Comparison •
CVE-2022-43622 – D-Link DIR-1935 HNAP_AUTH Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-43622
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of Login requests to the web management portal. When parsing the HNAP_AUTH header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. • https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310 https://www.zerodayinitiative.com/advisories/ZDI-22-1491 • CWE-121: Stack-based Buffer Overflow •
CVE-2022-43619 – D-Link DIR-1935 ConfigFileUpload Format String Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-43619
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of ConfigFileUpload requests to the web management portal. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to execute code in the context of root. • https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10310 https://www.zerodayinitiative.com/advisories/ZDI-22-1493 • CWE-134: Use of Externally-Controlled Format String •