VYPR
Unrated severityNVD Advisory· Published Jan 26, 2023· Updated Nov 4, 2025

CVE-2022-41021

CVE-2022-41021

Description

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null) options WORD' command template.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in Siretta QUARTZ-GOLD router's DetranCLI allows remote authenticated attackers to execute arbitrary commands via a crafted VPN configuration command.

Vulnerability

The vulnerability exists in the DetranCLI command parsing functionality of the Siretta QUARTZ-GOLD industrial router, specifically in firmware version G5.0.1.5-210720-141020. The flaw is a stack-based buffer overflow in the function handling the vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null) options WORD command template. The overflow occurs during sprintf operations where user-supplied parameters are copied into a fixed-size stack buffer without proper bounds checking, as described in [1].

Exploitation

An attacker must first obtain administrative access to the router's CLI (e.g., via SSH or console) to reach the vulnerable command parser. With privileged access, the attacker can send a sequence of crafted requests that supply excessively long parameters for fields like the tunnel name (WORD) or the password value. The sprintf function then writes beyond the allocated stack buffer, overwriting adjacent memory. This can corrupt the stack and allow redirection of execution flow, as detailed in [1].

Impact

Successful exploitation enables arbitrary command execution with root privileges on the router. This gives the attacker full control over the device, including the ability to reconfigure network settings, intercept traffic, install persistent malware, or pivot to other devices on the network. The CVSSv3 score is 7.2, indicating high impact on confidentiality, integrity, and availability [1].

Mitigation

Siretta has not yet released a patched firmware version for this vulnerability as of the publication date. Users are advised to restrict administrative access to the router to trusted networks only, use strong passwords, and monitor for suspicious activity. The vulnerable version is G5.0.1.5-210720-141020; upgrading to a fixed release when available is the recommended mitigation. This vulnerability is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Range: G5.0.1.5-210720-141020
  • Siretta/QUARTZ-GOLDv5
    Range: G5.0.1.5-210720-141020

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.