Tag

#Stack-Based Buffer Overflow

blogCRITICAL 9.8

Understanding and Defending Against CVE-2026-85504: A Critical Stack-Based Buffer Overflow in FreeIPMI

CVE-2026-85504 is a critical stack-based buffer overflow vulnerability in FreeIPMI, a software for managing and monitoring IPMI-enabled devices. This vulnerability, with a CVSS score of 9.8, allows remote attackers to execute arbitrary code on affected systems. The vulnerability exists in the _ipmi_sel_oem_fujitsu_get_sel_entry_long_text function and is triggered by malformed Fujitsu SEL long-text responses. Understanding and defending against this vulnerability is crucial for maintaining the security of IPMI-enabled devices.

1 source
articleCRITICAL 9.9

CVE-2026-76004: Critical Stack-Based Buffer Overflow in UTT HiPER 1250GW

A critical stack-based buffer overflow vulnerability (CVE-2026-76004) has been discovered in UTT HiPER 1250GW up to version 3.2.7-210907-180535. The vulnerability affects the HTTP Handler component and can be exploited remotely. The CVSS score is 9.9, indicating a high severity. Although not actively exploited, the exploit has been publicly disclosed. Immediate patching or mitigation is recommended.

1 source
newsHIGH 8.8

CVE-2026-19791: Tenda G0 Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability exists in Tenda G0 up to version 20260625, affecting the httpd web management interface. An attacker can exploit this vulnerability remotely by manipulating the staticRouteNet argument in the addStaticRoute function, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 8.8 and is considered high severity.

1 source
articleHIGH 8.8

CVE-2026-19788: Critical Stack-Based Buffer Overflow in Tenda AC1206 Router

A critical stack-based buffer overflow vulnerability (CVE-2026-19788) has been discovered in the Tenda AC1206 router, specifically in the httpd web management interface. The vulnerability has a CVSS score of 8.8 and can be exploited remotely without authentication, allowing attackers to potentially gain control over affected devices. The exploit has been made public, increasing the risk of active exploitation. Organizations using the affected version (15.03.06.23_multi_TD01) should apply patches or mitigations immediately.

1 source
blogHIGH 8.8

CVE-2026-16097: Understanding and Defending Against Stack-Based Buffer Overflow in Shibby Tomato

This educational analysis delves into CVE-2026-16097, a stack-based buffer overflow vulnerability in Shibby Tomato 1.28. The vulnerability affects the Scheduler Name Handler component and allows for remote exploitation, leading to potential confidentiality, integrity, and availability impacts. We will explore the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies to mitigate this threat.

1 source
articleHIGH 8.8

CVE-2026-13518: Tenda JD12L Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability has been discovered in Tenda JD12L version 16.03.53.23. The vulnerability affects the fromAddressNat function in the /goform/addressNat file and can be exploited remotely. The CVSS score for this vulnerability is 8.8, indicating a high severity. Although it is not currently being actively exploited, the exploit has been disclosed to the public and may be used.

1 source