ZeroHour

CVE-2022-4873

PoC
CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

Vendors
netcommwireless
Products
nf20 firmware, nf20mesh firmware, nl1902 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news