CVE-2007-4915

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
17/09/2007
Last modified:
09/04/2025

Description

The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:boa:boa_webserver:0.93.15:*:*:*:*:*:*:*