Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-8985

Опубликовано: 21 фев. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 9
EPSS Высокий

Описание

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:netis-systems:wf2411_firmware:2.1.36123:*:*:*:*:*:*:*
cpe:2.3:h:netis-systems:wf2411:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:netis-systems:wf2880_firmware:2.1.36123:*:*:*:*:*:*:*
cpe:2.3:h:netis-systems:wf2880:-:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.71811
Высокий

9.8 Critical

CVSS3

9 Critical

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.

EPSS

Процентиль: 99%
0.71811
Высокий

9.8 Critical

CVSS3

9 Critical

CVSS2

Дефекты

CWE-306