From 3af1b5c4d2434760b0d0f587b13b4bb25cc49967 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 1 Aug 2024 03:32:14 +0000 Subject: [PATCH] Publish Advisories GHSA-mh49-xg6j-w6xh GHSA-2pxp-hm79-mvqx GHSA-4473-886f-f22q GHSA-4g6m-wpfm-pfxv GHSA-73q4-cgh7-2r7w GHSA-c627-r4px-c33f GHSA-hjrp-8hpj-3p5p GHSA-m48x-h45r-5jvm GHSA-p2wx-946c-4xxv GHSA-vp2r-2xj4-fq27 GHSA-w25h-8579-q2hj --- .../GHSA-mh49-xg6j-w6xh.json | 2 +- .../GHSA-2pxp-hm79-mvqx.json | 54 +++++++++++++++++++ .../GHSA-4473-886f-f22q.json | 39 ++++++++++++++ .../GHSA-4g6m-wpfm-pfxv.json | 39 ++++++++++++++ .../GHSA-73q4-cgh7-2r7w.json | 42 +++++++++++++++ .../GHSA-c627-r4px-c33f.json | 54 +++++++++++++++++++ .../GHSA-hjrp-8hpj-3p5p.json | 54 +++++++++++++++++++ .../GHSA-m48x-h45r-5jvm.json | 54 +++++++++++++++++++ .../GHSA-p2wx-946c-4xxv.json | 39 ++++++++++++++ .../GHSA-vp2r-2xj4-fq27.json | 54 +++++++++++++++++++ .../GHSA-w25h-8579-q2hj.json | 54 +++++++++++++++++++ 11 files changed, 484 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hjrp-8hpj-3p5p/GHSA-hjrp-8hpj-3p5p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m48x-h45r-5jvm/GHSA-m48x-h45r-5jvm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p2wx-946c-4xxv/GHSA-p2wx-946c-4xxv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vp2r-2xj4-fq27/GHSA-vp2r-2xj4-fq27.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json diff --git a/advisories/unreviewed/2024/01/GHSA-mh49-xg6j-w6xh/GHSA-mh49-xg6j-w6xh.json b/advisories/unreviewed/2024/01/GHSA-mh49-xg6j-w6xh/GHSA-mh49-xg6j-w6xh.json index 632d89241b1..a82f9a69c2e 100644 --- a/advisories/unreviewed/2024/01/GHSA-mh49-xg6j-w6xh/GHSA-mh49-xg6j-w6xh.json +++ b/advisories/unreviewed/2024/01/GHSA-mh49-xg6j-w6xh/GHSA-mh49-xg6j-w6xh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh49-xg6j-w6xh", - "modified": "2024-01-31T00:30:17Z", + "modified": "2024-08-01T03:30:46Z", "published": "2024-01-24T06:30:18Z", "aliases": [ "CVE-2024-22372" diff --git a/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json b/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json new file mode 100644 index 00000000000..f24a86de397 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2pxp-hm79-mvqx/GHSA-2pxp-hm79-mvqx.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pxp-hm79-mvqx", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-7332" + ], + "details": "A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7332" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/CP450/product.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273255" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273255" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.378357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json b/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json new file mode 100644 index 00000000000..13676c0cc73 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4473-886f-f22q", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-39607" + ], + "details": "OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39607" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN06672778" + }, + { + "type": "WEB", + "url": "https://www.elecom.co.jp/news/security/20240730-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json b/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json new file mode 100644 index 00000000000..242fb34d1ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g6m-wpfm-pfxv", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-40883" + ], + "details": "Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40883" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN06672778" + }, + { + "type": "WEB", + "url": "https://www.elecom.co.jp/news/security/20240730-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json b/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json new file mode 100644 index 00000000000..d454287181f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73q4-cgh7-2r7w", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-6687" + ], + "details": "The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly accessible and contain sensitive information such as sender and receiver names, phone numbers, physical addresses, and email addresses", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6687" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3127496%40ctt-expresso-para-woocommerce&new=3127496%40ctt-expresso-para-woocommerce&sfp_email=&sfph_mail=#file25" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/13088645-8233-40fb-8755-cbdf44c0eaf7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json b/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json new file mode 100644 index 00000000000..156227dc7d7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c627-r4px-c33f/GHSA-c627-r4px-c33f.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c627-r4px-c33f", + "modified": "2024-08-01T03:30:47Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-7335" + ], + "details": "A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273258 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7335" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/EX200/getSaveConfig.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273258" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273258" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hjrp-8hpj-3p5p/GHSA-hjrp-8hpj-3p5p.json b/advisories/unreviewed/2024/08/GHSA-hjrp-8hpj-3p5p/GHSA-hjrp-8hpj-3p5p.json new file mode 100644 index 00000000000..419be60177d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hjrp-8hpj-3p5p/GHSA-hjrp-8hpj-3p5p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjrp-8hpj-3p5p", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-7333" + ], + "details": "A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument week/sTime/eTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273256. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7333" + }, + { + "type": "WEB", + "url": "https://github.com/135a/IoT-vulnerable/blob/main/TOTOLINK/N350RT/setParentalRules.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273256" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273256" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379281" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m48x-h45r-5jvm/GHSA-m48x-h45r-5jvm.json b/advisories/unreviewed/2024/08/GHSA-m48x-h45r-5jvm/GHSA-m48x-h45r-5jvm.json new file mode 100644 index 00000000000..b852b4cc3d2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m48x-h45r-5jvm/GHSA-m48x-h45r-5jvm.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m48x-h45r-5jvm", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-7334" + ], + "details": "A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273257 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7334" + }, + { + "type": "WEB", + "url": "https://github.com/ruan-uer/create/blob/main/IoT-vulnerable/TOTOLINK/EX1200/UploadCustomModule.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273257" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273257" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379286" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p2wx-946c-4xxv/GHSA-p2wx-946c-4xxv.json b/advisories/unreviewed/2024/08/GHSA-p2wx-946c-4xxv/GHSA-p2wx-946c-4xxv.json new file mode 100644 index 00000000000..ab618aa4fec --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p2wx-946c-4xxv/GHSA-p2wx-946c-4xxv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2wx-946c-4xxv", + "modified": "2024-08-01T03:30:46Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-34021" + ], + "details": "Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34021" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN06672778" + }, + { + "type": "WEB", + "url": "https://www.elecom.co.jp/news/security/20240730-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T02:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vp2r-2xj4-fq27/GHSA-vp2r-2xj4-fq27.json b/advisories/unreviewed/2024/08/GHSA-vp2r-2xj4-fq27/GHSA-vp2r-2xj4-fq27.json new file mode 100644 index 00000000000..31be72ae99f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vp2r-2xj4-fq27/GHSA-vp2r-2xj4-fq27.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp2r-2xj4-fq27", + "modified": "2024-08-01T03:30:47Z", + "published": "2024-08-01T03:30:46Z", + "aliases": [ + "CVE-2024-7336" + ], + "details": "A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273259. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7336" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/EX200/loginauth.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273259" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273259" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379314" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T03:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json b/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json new file mode 100644 index 00000000000..1c794a23e0e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w25h-8579-q2hj/GHSA-w25h-8579-q2hj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w25h-8579-q2hj", + "modified": "2024-08-01T03:30:47Z", + "published": "2024-08-01T03:30:47Z", + "aliases": [ + "CVE-2024-7337" + ], + "details": "A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7337" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/EX1200/loginauth.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273260" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273260" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T03:15:01Z" + } +} \ No newline at end of file