Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Htek UC902 VoIP phone web management interface contains several buffer overflow vulnerabilities in the firmware version 2.0.4.4.46, which allow an attacker to crash the device (DoS) without authentication or execute code (authenticated as a user) to spawn a remote shell as a root user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Htek UC902 VoIP phone 缓冲区错误漏洞
Vulnerability Description
Htek UC902 VoIP phone是中国汉龙科技(Htek)公司的一款IP电话。 使用2.0.4.4.46版本固件的Htek UC902 VoIP phone中的Web管理界面存在缓冲区错误漏洞。该漏洞源于网络系统或产品在内存上执行操作时,未正确验证数据边界,导致向关联的其他内存位置上执行了错误的读写操作。攻击者可利用该漏洞导致缓冲区溢出或堆溢出等。
CVSS Information
N/A
Vulnerability Type
N/A