Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4gj-g96p-mj65

Опубликовано: 02 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of userInfo. When userInfo is passed into the addAuthUser function and processed by sscanf without size validation, it could lead to buffer overflow.

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of userInfo. When userInfo is passed into the addAuthUser function and processed by sscanf without size validation, it could lead to buffer overflow.

EPSS

Процентиль: 48%
0.00649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addAuthUser` function and processed by `sscanf` without size validation, it could lead to buffer overflow.

CVSS3: 9.8
fstec
6 месяцев назад

Уязвимость функции addAuthUser (goform/formAddWebAuthUse) микропрограммного обеспечения маршрутизаторов Tenda W20E, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 48%
0.00649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120