VYPR
Unrated severityNVD Advisory· Published Dec 23, 2022· Updated Apr 15, 2025

CVE-2022-46568

CVE-2022-46568

Description

D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack overflow in D-Link DIR-882 and DIR-878 SetSysEmailSettings module via AccountPassword allows authenticated remote attackers to potentially execute arbitrary code.

Vulnerability

A stack overflow vulnerability exists in the SetSysEmailSettings module of D-Link DIR-882 (firmware version DIR882A1_FW130B06) and DIR-878 (firmware version DIR_878_FW1.30B08) routers [1][2]. The AccountPassword parameter, obtained from the SOAP request, is copied into a stack buffer without proper bounds checking. The data is then passed through a decryption function and a hex-decoding loop, ultimately overflowing a local stack variable (v6) [1][2].

Exploitation

An attacker must have network access to the router's web interface and valid administrative credentials (the SetSysEmailSettings action requires authentication). The exploit is delivered via a crafted HTTP POST request to /HNAP1/ with a maliciously long AccountPassword value in the XML body [1][2]. The overflow occurs during the subsequent decryption and hex-decoding operations, overwriting adjacent stack memory [1][2].

Impact

Successful exploitation can corrupt stack data, potentially leading to arbitrary code execution with root privileges (the router runs as root). At a minimum, the overflow causes a denial of service by crashing the device [1][2].

Mitigation

As of the publication date (2022-12-23), D-Link has not released a firmware update to address this vulnerability. The affected models may be end-of-life; users should check the D-Link security bulletin for any future patches [3]. No workaround is available. This CVE is not listed in the Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Dlink/DIR882cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: DIR882A1_FW130B06
  • Dlink/DIR878llm-fuzzy
    Range: DIR_878_FW1.30B08

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.