ZeroHour

CVE-2019-12325

PoC
CVSS 3.1
8.8 high
EPSS
2%p79
Published
()
Modified
Description

The Htek UC902 VoIP phone web management interface contains several buffer overflow vulnerabilities in the firmware version 2.0.4.4.46, which allow an attacker to crash the device (DoS) without authentication or execute code (authenticated as a user) to spawn a remote shell as a root user.

Vendors
htek
Products
uc902 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.