CVE-2019-8985
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.
En Netis WF211, con la versión de firmware 2.1.36123, y otros dispositivos de Netis (posiblemente desde WF2411 hasta WF2800), hay un desbordamiento de búfer basado en pila que no precisa de autenticación. Esto puede conducir a una denegación de servicio (reinicio del dispositivo) o a la ejecución remota de código. Esta vulnerabilidad puede ser desencadenada por una petición GET con una cabecera HTTP larga "Authorization: Basic" que se gestiona de manera adecuada en user_auth->user_ok en /bin/boa.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-21 CVE Reserved
- 2019-02-21 CVE Published
- 2022-07-19 First Exploit
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/Squirre17/CVE-2019-8985 | 2022-07-19 | |
https://github.com/WhooAmii/whooamii.github.io/blob/master/2018/netis/buffer%20overflow.md | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netis-systems Search vendor "Netis-systems" | Wf2411 Firmware Search vendor "Netis-systems" for product "Wf2411 Firmware" | 2.1.36123 Search vendor "Netis-systems" for product "Wf2411 Firmware" and version "2.1.36123" | - |
Affected
| in | Netis-systems Search vendor "Netis-systems" | Wf2411 Search vendor "Netis-systems" for product "Wf2411" | - | - |
Safe
|
Netis-systems Search vendor "Netis-systems" | Wf2880 Firmware Search vendor "Netis-systems" for product "Wf2880 Firmware" | 2.1.36123 Search vendor "Netis-systems" for product "Wf2880 Firmware" and version "2.1.36123" | - |
Affected
| in | Netis-systems Search vendor "Netis-systems" | Wf2880 Search vendor "Netis-systems" for product "Wf2880" | - | - |
Safe
|