Stack based overflow on Netcomm router models NF20MESH, NF20, and NL1902
CVE-2022-4873

9.8CRITICAL

Key Information:

Vendor

Netcomm

Vendor
CVE Published:
11 January 2023

What is CVE-2022-4873?

A stack-based buffer overflow vulnerability exists in the sessionKey parameter of Netcomm router models NF20MESH, NF20, and NL1902. By supplying a maliciously crafted input, an attacker can overwrite the instruction pointer on the stack, which could lead to application crashes. This vulnerability highlights the importance of robust input validation and protocol handling in network devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

NF20 R6B025

NF20MESH R6B025

NL1902 R6B025

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.