PT-2023-30405 · Shenzhen Libituo Technology Co. · Lbt-T300-T310
Published
2023-11-30
·
Updated
2023-12-06
·
CVE-2023-47307
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 version 2.2.2.6
Description
The issue is related to a Buffer Overflow that allows attackers to cause a denial of service. This is achieved via the
ApCliAuthMode parameter in the "/apply.cgi" API endpoint.Recommendations
For version 2.2.2.6, consider disabling access to the "/apply.cgi" API endpoint or restricting the use of the
ApCliAuthMode parameter until a patch is available.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lbt-T300-T310