漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
Vulnerability Description
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
WAVLINK wn572 缓冲区错误漏洞
Vulnerability Description
WAVLINK wn572是中国WAVLINK公司的一款无线网络设备。 Wavlink WN572、WN570H、WN573、WN529、WN530、WN531、WN535、WN536、WN551、WN557和NU516 20260609及之前版本存在缓冲区错误漏洞,该漏洞源于lighttpd组件中upload.cgi文件的strcpy函数对HTTP_COOKIE参数操作不当,导致栈缓冲区溢出,攻击者可能远程发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A