Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqxx-7rgw-867q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

EPSS

Процентиль: 80%
0.0137
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

EPSS

Процентиль: 80%
0.0137
Низкий