Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service
Vulnerability Description
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows before a bounds check and is then passed to memcpy as a very large size. This issue is fixed v25.12.5.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
整数下溢(超界折返)
Vulnerability Title
OpenWrt 数字错误漏洞
Vulnerability Description
OpenWrt是OpenWRT社区开源的一套针对嵌入式设备的Linux操作系统。 OpenWrt 25.12.5之前版本存在数字错误漏洞,该漏洞源于Emergency Access Daemon的handle_send_a()函数中存在整数下溢,可能导致未经身份验证的攻击者通过发送特制UDP数据包使守护进程崩溃。
CVSS Information
N/A
Vulnerability Type
N/A