CVE-2024-41590

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.
Configurations

No configuration.

History

07 Oct 2024, 19:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-121

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Varios endpoints de CGI son vulnerables a desbordamientos de búfer, por parte de usuarios autenticados, debido a la falta de verificación de los límites en los parámetros pasados a través de solicitudes POST a la función strcpy en dispositivos DrayTek Vigor310 hasta 4.3.2.6.

03 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-03 19:15

Updated : 2024-10-07 19:37


NVD link : CVE-2024-41590

Mitre link : CVE-2024-41590

CVE.ORG link : CVE-2024-41590


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow