Stack Overflow Vulnerability in Trendnet TEW-820AP Boa HTTP Server
CVE-2024-50667

Currently unrated

Key Information:

Vendor

Trendnet

Status
Vendor
CVE Published:
11 November 2024

What is CVE-2024-50667?

The Trendnet TEW-820AP, running Boa HTTP server version 1.01.B01, is susceptible to a stack overflow vulnerability that occurs in the handling of IPv6 address forms. Specifically, the endpoints /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, and /boafrm/formDnsv6 do not properly validate input, enabling attackers to craft malicious payloads that can exploit this flaw. Proper precautions should be taken to secure the affected device configurations to mitigate the risk of potential exploitation.

References

Timeline

  • Vulnerability published

.