PT-2024-13886 · Realtek · Realtek Rtl819X Jungle Sdk

Francesco Benvenuto

·

Published

2024-07-08

·

Updated

2024-07-11

·

CVE-2023-50244

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Realtek rtl819x Jungle SDK version 3.4.11
Description Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities. This issue is related to the entry name request's parameter.
Recommendations For Realtek rtl819x Jungle SDK version 3.4.11, consider disabling the boa formIpQoS functionality until a patch is available. Restrict access to the vulnerable entry name parameter in the affected HTTP requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-50244

Affected Products

Realtek Rtl819X Jungle Sdk