Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-854w-ph8g-6mrh

Опубликовано: 25 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.7

Описание

An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem.

Customers that have not enabled Dynamic DNS on their modem are not vulnerable.

An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem.

Customers that have not enabled Dynamic DNS on their modem are not vulnerable.

EPSS

Процентиль: 15%
0.0005
Низкий

7.7 High

CVSS4

Дефекты

CWE-120

Связанные уязвимости

nvd
10 месяцев назад

An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled Dynamic DNS on their modem are not vulnerable.

EPSS

Процентиль: 15%
0.0005
Низкий

7.7 High

CVSS4

Дефекты

CWE-120