PT-2024-28773 · Unknown · Vilo 5 Mesh Wifi System

Published

2024-10-21

·

Updated

2024-10-23

·

CVE-2024-40085

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vilo 5 Mesh WiFi System versions <= 5.16.1.33
Description A Buffer Overflow issue in the local app set router wan function allows remote, unauthenticated attackers to execute arbitrary code. This is achieved by exploiting the pppoe username and pppoe password fields when they are larger than 128 bytes in length.
Recommendations For versions <= 5.16.1.33, update to a version later than 5.16.1.33 to resolve the issue. As a temporary workaround, consider restricting the length of the pppoe username and pppoe password fields to 128 bytes or less until a patch is available.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-40085

Affected Products

Vilo 5 Mesh Wifi System