Описание
A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.7-171114 (включая)
Одновременно
cpe:2.3:o:utt:512w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:utt:512w:3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00119
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
9 Critical
CVSS2
Дефекты
CWE-119
CWE-120
Связанные уязвимости
CVSS3: 8.8
github
около 1 месяца назад
A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
EPSS
Процентиль: 32%
0.00119
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
9 Critical
CVSS2
Дефекты
CWE-119
CWE-120