CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
52.7%
A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.This buffer overflow is in the next_page parameter in the gozila_cgi function.
Vendor | Product | Version | CPE |
---|---|---|---|
yifanwireless | yf325_firmware | 1.0_20221108 | cpe:2.3:o:yifanwireless:yf325_firmware:1.0_20221108:*:*:*:*:*:*:* |
yifanwireless | yf325 | - | cpe:2.3:h:yifanwireless:yf325:-:*:*:*:*:*:*:* |
[
{
"vendor": "Yifan",
"product": "YF325",
"versions": [
{
"version": "v1.0_20221108",
"status": "affected"
}
]
}
]