Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Angel Garcia Moreno

#31679of 53,633
8.1Total CVSS
Vulnerabilities · 1
PT-2022-14034
8.1
2022-05-24
Circutor · Compact Dc-S Basic · CVE-2022-1669
**Name of the Vulnerable Software and Affected Versions** Device management web portal (affected versions not specified) **Description** A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it would be copied to a second variable with a `strcpy` vulnerable function without checking its length. Because of this, it is possible to send a long address value to overflow the process stack, controlling the function return address. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.