Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87615
HistoryOct 10, 2022 - 12:00 a.m.

TOTOLINK NR1800X setLanguageCfg method buffer overflow vulnerability

2022-10-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
totolink nr1800x
buffer overflow
setlanguagecfg
code execution
china-based gion electronics
sip cpe
5g nr
wi-fi
nr1800x v9.1.0u.6279_b20210910
length validation
cnvd
data services

EPSS

0.001

Percentile

40.7%

TOTOLINK NR1800X is an outstanding 5G NR indoor Wi-Fi and SIP CPE from China-based Gion Electronics (TOTOLINK), designed to provide fast and convenient deployment of NR fixed data services for homes and offices.A buffer overflow vulnerability exists in TOTOLINK NR1800X V9.1.0u.6279_B20210910 version, which stems from The lang parameter of the setLanguageCfg method lacks length validation for the input data, which can be exploited by an attacker to cause code execution.

EPSS

0.001

Percentile

40.7%

Related for CNVD-2022-87615