Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument causes the service, and in practice the router, to crash or become unresponsive, resulting in a loss of availability for the device and connected users.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 16 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netis-systems dl4343 Firmware
|
|
| CPEs | cpe:2.3:o:netis-systems:dl4343_firmware:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Netis-systems dl4343 Firmware
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netis-systems
Netis-systems dl4322d |
|
| Vendors & Products |
Netis-systems
Netis-systems dl4322d |
Fri, 14 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument causes the service, and in practice the router, to crash or become unresponsive, resulting in a loss of availability for the device and connected users. | |
| Title | Netis DL4322D RTK 2.1.1 FTP Service DoS | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-14T22:52:24.858Z
Updated: 2025-11-17T20:35:53.147Z
Reserved: 2025-10-29T21:01:03.318Z
Link: CVE-2018-25125
Updated: 2025-11-17T20:35:49.896Z
Status : Awaiting Analysis
Published: 2025-11-14T23:15:41.967
Modified: 2025-11-18T14:06:55.963
Link: CVE-2018-25125
No data.