漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SNORE Interface Unauthenticated Remote Code Execution
Vulnerability Description
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker
with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:M/U:Red
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Vulnerability Title
Viasat多款产品 安全漏洞
Vulnerability Description
Viasat RM5110等都是美国Viasat公司的产品。Viasat RM5110是一款卫星调制解调器路由器。Viasat RM5111是一款卫星调制解调器路由器。Viasat RG1100是一款调制解调器路由器。 Viasat多款产品存在安全漏洞,该漏洞源于lighttpd中SNORE接口路径解析不安全,可能导致栈缓冲区溢出攻击。以下产品受到影响:Viasat RM4100、RM4200、EM4100、RM5110、RM5111、RG1000、RG1100、EG1000和EG1020。
CVSS Information
N/A
Vulnerability Type
N/A