Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc4v-92xf-xp3m

Опубликовано: 25 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.7

Описание

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

EPSS

Процентиль: 5%
0.00023
Низкий

7.7 High

CVSS4

Дефекты

CWE-120

Связанные уязвимости

redhat
8 месяцев назад

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

nvd
8 месяцев назад

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

EPSS

Процентиль: 5%
0.00023
Низкий

7.7 High

CVSS4

Дефекты

CWE-120