Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the malloc function.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
Yifan YF325 缓冲区错误漏洞
Vulnerability Description
Yifan YF325是亿帆(Yifan)公司的一个无线路由。 Yifan YF325 v1.0_20221108版本存在缓冲区错误漏洞,该漏洞源于gwcfg_cgi_set_manage_post_data功能存在缓冲区溢出漏洞。
CVSS Information
N/A
Vulnerability Type
N/A