Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-18952
HistoryJan 04, 2023 - 12:00 a.m.

TRENDnet TEW-755AP Stack Overflow Vulnerability (CNVD-2023-18952)

2023-01-0400:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
trendnet tew-755ap
stack overflow vulnerability
qcawifi.wifi\%d_vap\%d_maclist
kick_ban_wifi_mac_allow
arbitrary code execution
cnvd-2023-18952

EPSS

0.002

Percentile

61.9%

TRENDnet TEW-755AP is a router from Trendnet, Inc. TRENDnet TEW-755AP is vulnerable to a stack overflow vulnerability that originates from the qcawifi.wifi%d_vap%d_maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function. vap%d.maclist parameter in the function lacks size checking of the input data, which could be exploited by an attacker to execute arbitrary code on the system.

EPSS

0.002

Percentile

61.9%

Related for CNVD-2023-18952