chirpmyradio 的 CHIRP 程序在 39178db 之前版本中,存在通过精心构造的 CSV 数据进行 eval 注入的安全漏洞。该漏洞出现在 drivers/kenwood_itm.py 文件的 _clean_tmode 函数中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| chirpmyradio | CHIRP | < 39178dbfc4fece083ab9ed20286d6ae3a91a718e |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chirpmyradio | CHIRP | 0 ~ 39178dbfc4fece083ab9ed20286d6ae3a91a718e | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: crafted TXSIG payload was not evaluated (no code execution observed; _clean_tmode parses tones via kenwood_tone.parse_qtdqt, no eval call in this tree)
No comments yet