Stack-based buffer overflow in Weintek products - CVE-2023-38584
Published: October 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in cgi-bin command_wb.cgi. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
cMT-HDM
cMT3071
cMT3072
cMT3103
cMT3090
cMT3151
How to mitigate CVE-2023-38584
cMT-HDM - update to 20210205
cMT3071 - update to 20210219
cMT3072 - update to 20210219
cMT3103 - update to 20210219
cMT3090 - update to 20210219
cMT3151 - update to 20210219