VYPR
Unrated severityNVD Advisory· Published Jan 26, 2023· Updated Nov 4, 2025

CVE-2022-41019

CVE-2022-41019

Description

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null)' command template.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020, allowing arbitrary command execution via crafted requests.

Vulnerability

A stack-based buffer overflow vulnerability exists in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD router firmware version G5.0.1.5-210720-141020 [1]. Specifically, the overflow occurs in the function managing the vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null) command template. The issue arises from an unsafe use of sprintf to copy user-controlled parameters into a fixed-size stack buffer without proper bounds checking [1].

Exploitation

An attacker with high privileges (authenticated access to the router's CLI) can send a crafted sequence of network packets to trigger the overflow. The attacker must provide specially crafted values for the command parameters, such as exceeding buffer lengths. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates a network-accessible attack vector requiring high privileges and no user interaction [1].

Impact

Successful exploitation leads to arbitrary command execution on the router with root-level privileges, compromising confidentiality, integrity, and availability of the device. The attacker can gain full control over the router.

Mitigation

No vendor patch has been released as of the publication date (2023-01-26) [1]. Users should restrict network access to the router's management interface and monitor for vendor updates. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of that date [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Range: = G5.0.1.5-210720-141020
  • Siretta/QUARTZ-GOLDv5
    Range: G5.0.1.5-210720-141020

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.