CVE-2023-49351

A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:br-6478ac_firmware:1.23:*:*:*:*:*:*:*
cpe:2.3:h:edimax:br-6478ac:v2:*:*:*:*:*:*:*

History

30 Jan 2024, 13:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-787
Summary
  • (es) Una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria en el binario /bin/webs en la versión v1.23 del firmware Edimax BR6478AC V2 permite a los atacantes sobrescribir otros valores ubicados en la pila debido a un uso incorrecto de la función strcpy().
References () https://github.com/countfatcode/temp/blob/main/formUSBAccount/formUSBAccount.md - () https://github.com/countfatcode/temp/blob/main/formUSBAccount/formUSBAccount.md - Broken Link
CPE cpe:2.3:h:edimax:br-6478ac:v2:*:*:*:*:*:*:*
cpe:2.3:o:edimax:br-6478ac_firmware:1.23:*:*:*:*:*:*:*
First Time Edimax
Edimax br-6478ac
Edimax br-6478ac Firmware

16 Jan 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 19:15

Updated : 2024-01-30 13:56


NVD link : CVE-2023-49351

Mitre link : CVE-2023-49351

CVE.ORG link : CVE-2023-49351


JSON object : View

Products Affected

edimax

  • br-6478ac_firmware
  • br-6478ac
CWE
CWE-787

Out-of-bounds Write