CVE-2025-45835: Null Pointer Dereference
A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENTLENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45835?
CVE-2025-45835 is considered a high severity vulnerability due to its potential to cause system crashes.
How do I fix CVE-2025-45835?
To mitigate CVE-2025-45835, it is recommended to update the Netis WF2880 firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2025-45835?
CVE-2025-45835 specifically affects the Netis WF2880 model running version v2.1.40207.
What type of vulnerability is CVE-2025-45835?
CVE-2025-45835 is classified as a null pointer dereference vulnerability.
Can CVE-2025-45835 be exploited remotely?
Yes, attackers can exploit CVE-2025-45835 remotely by manipulating the CONTENT_LENGTH environment variable.