Expressvpn · Expressvpn Router · CVE-2020-29238
Name of the Vulnerable Software and Affected Versions:
ExpressVPN Router version 1
Description:
An integer buffer overflow in the Nginx webserver allows remote attackers to obtain sensitive information when the server is running as a reverse proxy via specially crafted requests.
Recommendations:
For ExpressVPN Router version 1, update to a version that fixes the integer buffer overflow issue in the Nginx webserver. As a temporary workaround, consider restricting access to the reverse proxy functionality until a patch is available.