PT-2024-28773 · Unknown · Vilo 5 Mesh Wifi System
Published
2024-10-21
·
Updated
2024-10-23
·
CVE-2024-40085
CVSS v3.1
9.6
Critical
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vilo 5 Mesh WiFi System versions <= 5.16.1.33
Description
A Buffer Overflow issue in the
local app set router wan function allows remote, unauthenticated attackers to execute arbitrary code. This is achieved by exploiting the pppoe username and pppoe password fields when they are larger than 128 bytes in length.Recommendations
For versions <= 5.16.1.33, update to a version later than 5.16.1.33 to resolve the issue.
As a temporary workaround, consider restricting the length of the
pppoe username and pppoe password fields to 128 bytes or less until a patch is available.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vilo 5 Mesh Wifi System