PT-2024-31616 · Zte · Zte Routers

Wr3Nchsr

·

Published

2024-09-16

·

Updated

2024-09-20

·

CVE-2024-45413

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ZTE routers (affected versions not specified)
Description: The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in the rsa decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, and the decrypted data is stored on the stack without checking its length. An authenticated attacker can get remote code execution (RCE) as root by exploiting this vulnerability.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-45413

Affected Products

Zte Routers