PT-2018-14538 · Guardzilla · Guardzilla Gz621W

Published

2018-12-31

·

Updated

2025-05-06

·

CVE-2018-18601

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Guardzilla GZ621W version 0.5.1.4
Description The issue is related to a Buffer Overflow in the TK set deviceModel req handle function, which is part of the cloud communication component.
Recommendations For Guardzilla GZ621W version 0.5.1.4, consider restricting access to the cloud communication component until a patch is available. As a temporary workaround, disabling the TK set deviceModel req handle function may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2018-18601

Affected Products

Guardzilla Gz621W