PT-2024-13829 · Realtek · Realtek Rtl819X Jungle Sdk
Francesco Benvenuto
·
Published
2024-07-08
·
Updated
2024-07-11
·
CVE-2023-49867
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Realtek rtl819x Jungle SDK version 3.4.11
Description
A stack-based buffer overflow vulnerability exists in the boa formWsc functionality. This can be triggered by a specially crafted series of HTTP requests, potentially leading to remote code execution. An attacker can exploit this issue by sending a series of HTTP requests.
Recommendations
For Realtek rtl819x Jungle SDK version 3.4.11, consider disabling the boa formWsc functionality until a patch is available to prevent potential remote code execution. Restrict access to the vulnerable functionality to minimize the risk of exploitation. Avoid using the vulnerable SDK version in production environments until a fixed version is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realtek Rtl819X Jungle Sdk