PT-2020-16458 · Acme+1 · Mini Httpd+1

Published

2020-10-23

·

Updated

2024-08-04

·

CVE-2020-26561

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Belkin LINKSYS WRT160NL version 1.0.04.002 US 20130619
Description The issue is a stack-based buffer overflow due to the use of sprintf in the create dir function of mini httpd. This can lead to arbitrary code execution if successfully exploited. It's noted that this only affects products that are no longer supported by the maintainer.
Recommendations For Belkin LINKSYS WRT160NL version 1.0.04.002 US 20130619, as a temporary workaround, consider disabling the create dir function in mini httpd until a patch is available. However, since the products are no longer supported, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2020-26561

Affected Products

Linksys Wrt160N
Mini Httpd