Buffer overflow in RV215W Wireless-N VPN Router and RV110W Wireless-N VPN Firewall - CVE-2020-3331

 

Buffer overflow in RV215W Wireless-N VPN Router and RV110W Wireless-N VPN Firewall - CVE-2020-3331

Published: July 22, 2020


Vulnerability identifier: #VU31756
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3331
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the web-based management interface. A remote attacker can send a specially crafted request, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

RV215W Wireless-N VPN Router
RV110W Wireless-N VPN Firewall

How to mitigate CVE-2020-3331

Install updates from vendor's website.

RV215W Wireless-N VPN Router - update to 1.3.1.7
RV110W Wireless-N VPN Firewall - update to 1.2.2.8

External References

Related Security Bulletins