Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument causes the service, and in practice the router, to crash or become unresponsive, resulting in a loss of availability for the device and connected users.
History

Sun, 16 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Netis-systems dl4343 Firmware
CPEs cpe:2.3:o:netis-systems:dl4343_firmware:-:*:*:*:*:*:*:*
Vendors & Products Netis-systems dl4343 Firmware

Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Netis-systems
Netis-systems dl4322d
Vendors & Products Netis-systems
Netis-systems dl4322d

Fri, 14 Nov 2025 23:00:00 +0000

Type Values Removed Values Added
Description Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument causes the service, and in practice the router, to crash or become unresponsive, resulting in a loss of availability for the device and connected users.
Title Netis DL4322D RTK 2.1.1 FTP Service DoS
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-16T13:13:14.500Z

Reserved: 2025-10-29T21:01:03.318Z

Link: CVE-2018-25125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-14T23:15:41.967

Modified: 2025-11-14T23:15:41.967

Link: CVE-2018-25125

cve-icon Redhat

No data.