Stack Overflow Vulnerability in H3C Magic R100 Router
CVE-2022-30923
9.8CRITICAL
Summary
The H3C Magic R100 router exhibits a stack overflow vulnerability that can be exploited through the Asp_SetTimingtimeWifiAndLed parameter in the /goform/aspForm endpoint. This flaw allows potential attackers to cause service disruption or execute arbitrary code, compromising the integrity and availability of affected devices. It highlights the critical need for robust network security measures to protect against such vulnerabilities, especially in Internet of Things (IoT) deployments.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved