CVE-2011-1323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
09/05/2011
Last modified:
11/04/2025

Description

Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:yamaha:rt100i:1.02.05:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.02.08:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.02.16:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.03.08:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.03.12:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.03.15:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.03.24:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.03.25:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.03.30:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.04.03:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.04.06:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.04.09:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.05.05:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.05.07:*:*:*:*:*:*:*
cpe:2.3:o:yamaha:rt100i:1.05.09:*:*:*:*:*:*:*