// For flags

CVE-2019-19945

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.

uhttpd en OpenWrt versiones hasta 18.06.5 y versiones 19.x hasta 19.07.0-rc2, presenta un error de la propiedad signedness de enteros. Esto conlleva a un acceso fuera de límites en un búfer de la pila y un bloqueo posterior. Se puede activar con una petición HTTP POST en un script CGI, especificando tanto "Transfer-Encoding: chunked" como un valor negativo grande de Content-Length.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-12-23 CVE Reserved
  • 2020-03-16 CVE Published
  • 2022-06-27 First Exploit
  • 2024-08-05 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-125: Out-of-bounds Read
  • CWE-681: Incorrect Conversion between Numeric Types
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openwrt
Search vendor "Openwrt"
Openwrt
Search vendor "Openwrt" for product "Openwrt"
>= 18.06.0 <= 18.06.5
Search vendor "Openwrt" for product "Openwrt" and version " >= 18.06.0 <= 18.06.5"
-
Affected
Openwrt
Search vendor "Openwrt"
Openwrt
Search vendor "Openwrt" for product "Openwrt"
19.07.0
Search vendor "Openwrt" for product "Openwrt" and version "19.07.0"
-
Affected
Openwrt
Search vendor "Openwrt"
Openwrt
Search vendor "Openwrt" for product "Openwrt"
19.07.0
Search vendor "Openwrt" for product "Openwrt" and version "19.07.0"
rc1
Affected
Openwrt
Search vendor "Openwrt"
Openwrt
Search vendor "Openwrt" for product "Openwrt"
19.07.0
Search vendor "Openwrt" for product "Openwrt" and version "19.07.0"
rc2
Affected