Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84m3-vwgv-cp2x

Опубликовано: 02 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of nptr. When this value is passed into the getMibPrefix function and concatenated using sprintf without proper size validation, it could lead to a buffer overflow vulnerability.

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of nptr. When this value is passed into the getMibPrefix function and concatenated using sprintf without proper size validation, it could lead to a buffer overflow vulnerability.

EPSS

Процентиль: 48%
0.00649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerability.

CVSS3: 9.8
fstec
6 месяцев назад

Уязвимость функции getMibPrefix (goform/formWifiFilterRulesAdd) микропрограммного обеспечения маршрутизаторов Tenda W20E, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 48%
0.00649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120