Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-34087

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BPQ32是Groups开源的一款用于分组无线电通信的软件。 BPQ32 6.0.24.1版本存在安全漏洞,该漏洞源于HTTP服务器存在基于SEH的缓冲区溢出,允许有权访问Web终端的远程攻击者通过HTTP POST /TermInput请求实现远程代码执行。

AI Predicted 9.8 Difficulty: Trivial EPSS 1.19% · P65

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-34087

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
BPQ32 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
BPQ32是Groups开源的一款用于分组无线电通信的软件。 BPQ32 6.0.24.1版本存在安全漏洞,该漏洞源于HTTP服务器存在基于SEH的缓冲区溢出,允许有权访问Web终端的远程攻击者通过HTTP POST /TermInput请求实现远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2024-34087

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-34087

登录查看更多情报信息。

Other References for CVE-2024-34087 (1)

Other References for CVE-2024-34087 (3)

Same Patch Batch · n/a · 2024-08-26 · 35 CVEs total

CVE-2024-44796 PicUploader 安全漏洞
CVE-2024-42791 Kashipara Music Management System 安全漏洞
CVE-2024-42789 Kashipara Music Management System 安全漏洞
CVE-2024-45265 SkySystem Arfa-CMS 安全漏洞
CVE-2024-41444 SeaCMS 安全漏洞
CVE-2024-28077 GL.iNet多款产品 安全漏洞
CVE-2024-44797 Gazelle 安全漏洞
CVE-2024-44795 Gazelle 安全漏洞
CVE-2024-44793 Gazelle 安全漏洞
CVE-2024-42787 Kashipara Music Management System 安全漏洞
CVE-2024-44794 PicUploader 安全漏洞
CVE-2024-42913 RuoYi 安全漏洞
CVE-2024-42906 TestLink 安全漏洞
CVE-2024-42816 FastAPI Admin 安全漏洞
CVE-2024-42792 Kashipara Music Management System 安全漏洞
CVE-2024-42818 FastAPI Admin 安全漏洞
CVE-2024-42790 Kashipara Music Management System 安全漏洞
CVE-2024-44558 Tenda AX1806 安全漏洞
CVE-2024-45241 CentralSquare CryWolf 安全漏洞
CVE-2024-39097 Gnuboard 安全漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2024-34087

No comments yet


Leave a comment