Multiple Xiongmai NVR devices, including MBD6304T V4.02...
Critical severity
Unreviewed
Published
Mar 29, 2023
to the GitHub Advisory Database
•
Updated Apr 15, 2023
Description
Published by the National Vulnerability Database
Mar 28, 2023
Published to the GitHub Advisory Database
Mar 29, 2023
Last updated
Apr 15, 2023
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.
References