From 9daf622c03c985275c7c1dbd2ba65c5a263b4482 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 19 Apr 2025 15:31:57 +0000 Subject: [PATCH] Publish Advisories GHSA-5hmc-37pv-999m GHSA-5pf2-m3f5-xwwj GHSA-wvcx-j62q-45qw --- .../GHSA-5hmc-37pv-999m.json | 56 +++++++++++++++++++ .../GHSA-5pf2-m3f5-xwwj.json | 56 +++++++++++++++++++ .../GHSA-wvcx-j62q-45qw.json | 52 +++++++++++++++++ 3 files changed, 164 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-5hmc-37pv-999m/GHSA-5hmc-37pv-999m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5pf2-m3f5-xwwj/GHSA-5pf2-m3f5-xwwj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wvcx-j62q-45qw/GHSA-wvcx-j62q-45qw.json diff --git a/advisories/unreviewed/2025/04/GHSA-5hmc-37pv-999m/GHSA-5hmc-37pv-999m.json b/advisories/unreviewed/2025/04/GHSA-5hmc-37pv-999m/GHSA-5hmc-37pv-999m.json new file mode 100644 index 00000000000..d3ce8d8e653 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5hmc-37pv-999m/GHSA-5hmc-37pv-999m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hmc-37pv-999m", + "modified": "2025-04-19T15:30:23Z", + "published": "2025-04-19T15:30:23Z", + "aliases": [ + "CVE-2025-3802" + ], + "details": "A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file /bin/httpd. The manipulation of the argument pingIP leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3802" + }, + { + "type": "WEB", + "url": "https://github.com/02Tn/vul/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305656" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305656" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554746" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5pf2-m3f5-xwwj/GHSA-5pf2-m3f5-xwwj.json b/advisories/unreviewed/2025/04/GHSA-5pf2-m3f5-xwwj/GHSA-5pf2-m3f5-xwwj.json new file mode 100644 index 00000000000..f0cbe6312a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5pf2-m3f5-xwwj/GHSA-5pf2-m3f5-xwwj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pf2-m3f5-xwwj", + "modified": "2025-04-19T15:30:23Z", + "published": "2025-04-19T15:30:23Z", + "aliases": [ + "CVE-2025-3803" + ], + "details": "A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file /bin/httpd. The manipulation of the argument rebootDate leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3803" + }, + { + "type": "WEB", + "url": "https://github.com/02Tn/vul/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305657" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305657" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554756" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wvcx-j62q-45qw/GHSA-wvcx-j62q-45qw.json b/advisories/unreviewed/2025/04/GHSA-wvcx-j62q-45qw/GHSA-wvcx-j62q-45qw.json new file mode 100644 index 00000000000..374d5d6e7a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wvcx-j62q-45qw/GHSA-wvcx-j62q-45qw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvcx-j62q-45qw", + "modified": "2025-04-19T15:30:23Z", + "published": "2025-04-19T15:30:23Z", + "aliases": [ + "CVE-2025-3801" + ], + "details": "A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3801" + }, + { + "type": "WEB", + "url": "https://github.com/yaowenxiao721/Poc/blob/main/One-API/One-API-poc.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554702" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T14:15:38Z" + } +} \ No newline at end of file