CVE-2020-26762
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthenticated, unauthorized attacker to perform remote-code-execution due to a crafted GET-Request. The overflow occurs in binary ipcam_cgi due to a missing type check in function doGetSysteminfo(). This has been fixed in version: IC-3116W v3.08.
Se presenta un desbordamiento de búfer en la región stack de la memoria en la Cámara IP Edimax IC-3116W (versión v3.06) e IC-3140W (versión v3.07), que permite a un atacante no autorizado y no autenticado llevar a cabo una ejecución de código remota debido a una petición GET diseñada. El desbordamiento ocurre en el binario ipcam_cgi debido a una falta de comprobación de tipo en la función doGetSysteminfo(). Esto ha sido corregido en la versión: IC-3116W v3.08
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-07 CVE Reserved
- 2020-12-01 CVE Published
- 2024-04-05 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Edimax Search vendor "Edimax" | Ic-3116w Firmware Search vendor "Edimax" for product "Ic-3116w Firmware" | 3.06 Search vendor "Edimax" for product "Ic-3116w Firmware" and version "3.06" | - |
Affected
| in | Edimax Search vendor "Edimax" | Ic-3116w Search vendor "Edimax" for product "Ic-3116w" | - | - |
Safe
|
Edimax Search vendor "Edimax" | Ic-3140w Firmware Search vendor "Edimax" for product "Ic-3140w Firmware" | 3.07 Search vendor "Edimax" for product "Ic-3140w Firmware" and version "3.07" | - |
Affected
| in | Edimax Search vendor "Edimax" | Ic-3140w Search vendor "Edimax" for product "Ic-3140w" | - | - |
Safe
|