VYPR
Unrated severityNVD Advisory· Published Jan 26, 2023· Updated Nov 4, 2025

CVE-2022-41002

CVE-2022-41002

Description

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null)' command template.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in Siretta QUARTZ-GOLD router's DetranCLI allows authenticated remote attackers to execute arbitrary commands.

Vulnerability

A stack-based buffer overflow vulnerability exists in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD firmware version G5.0.1.5-210720-141020. The flaw resides in the function that processes the no icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null) command template. When user-supplied parameters are copied into a fixed-size stack buffer using sprintf without proper bounds checking, an attacker can overflow the buffer and overwrite adjacent memory [1].

Exploitation

An attacker must have network access to the router and possess high privileges (administrative credentials) to interact with the DetranCLI interface. By sending a specially crafted network packet containing an overly long parameter in the vulnerable command template, the attacker triggers the buffer overflow. The sequence involves authenticating to the router's CLI and issuing the malformed command [1].

Impact

Successful exploitation allows the attacker to achieve arbitrary command execution with root privileges on the device. This results in full compromise of confidentiality, integrity, and availability, as the attacker can read, modify, or delete sensitive data, install malware, or disrupt router operations [1].

Mitigation

As of the publication date (2023-01-26), no official patch or firmware update has been released by Siretta to address this vulnerability. The vendor has not confirmed a fix timeline. As a workaround, restrict network access to the router's management interface to trusted hosts only and disable the DetranCLI service if not required. This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Range: = G5.0.1.5-210720-141020
  • Siretta/QUARTZ-GOLDv5
    Range: G5.0.1.5-210720-141020

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.