CVE-2022-26953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/04/2022
Last modified:
12/04/2022

Description

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the string is concatenated to the HTML body.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:digi:passport_firmware:*:*:*:*:*:*:*:* 1.5.1.1 (including)
cpe:2.3:h:digi:passport:-:*:*:*:*:*:*:*