An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HLevel1 Wbr 6013
HWLevel1all versionsLevel1 Wbr 6013 Firmware
OSLevel1rer4_a_v3411b_2t2r_lev_09_170623Realtek Rtl819x Jungle Software Development Kit
APPRealtek3.4.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2021-35395CRITICAL9.8⚠ KEVPL ✓same product
Wielokrotny stack buffer overflow i command injection w Realtek Jungle SDK
CVE-2021-35394CRITICAL9.8⚠ KEVPL ✓same product
Realtek Jungle SDK – RCE i command injection w narzędziu MP Daemon
CVE-2023-46685CRITICAL9.8PL ✓same product
Zakodowane na stałe hasło w usłudze telnetd routera LevelOne WBR-6013
CVE-2021-35393CRITICAL9.8PL ✓same product
Stack buffer overflow w Realtek Jungle SDK — RCE przez UPnP SUBSCRIBE
CVE-2023-34435HIGH7.2same product
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4....