CVE-2023-50244: Buffer Overflow
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the entryname request's parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50244?
CVE-2023-50244 has a high severity due to its potential for remote code execution.
How do I fix CVE-2023-50244?
To fix CVE-2023-50244, update the Realtek rtl819x Jungle SDK to version 3.4.12 or later.
What types of devices are affected by CVE-2023-50244?
CVE-2023-50244 affects devices using Realtek rtl819x Jungle SDK v3.4.11 and Level1 Wbr-6013 firmware version rer4_a_v3411b_2t2r_lev_09_170623.
What can an attacker do with CVE-2023-50244?
An attacker exploiting CVE-2023-50244 can execute arbitrary code remotely through specially crafted HTTP requests.
Is CVE-2023-50244 being actively exploited?
While there are no public reports confirming active exploitation of CVE-2023-50244, its nature makes it a significant risk.