On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T21:31:37.574Z

Reserved: 2019-02-21T00:00:00

Link: CVE-2019-8985

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-21T19:29:00.570

Modified: 2024-11-21T04:50:45.637

Link: CVE-2019-8985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses