CVE-2021-3304

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
26/01/2021
Last modified:
03/02/2021

Description

Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sagemcom:f\@st_3686_firmware:3.495:*:*:*:*:*:*:*
cpe:2.3:h:sagemcom:f\@st_3686:v2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools