vendor:
uc-httpd
by:
Andrew Watson
9.8
CVSS
CRITICAL
Buffer Overflow
120
CWE
Product Name: uc-httpd
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: YES
Related CWE: CVE-2018-10088
CPE: a:xiongmaitech:uc-httpd:1.0.0
Metasploit:
N/A
Platforms Tested: KKMoon DVR
2018
XiongMai uc-httpd 1.0.0 – Buffer Overflow
XiongMai uc-httpd 1.0.0 is vulnerable to a buffer overflow attack when a maliciously crafted POST request is sent to the web server. This can be exploited to execute arbitrary code on the vulnerable system.
Mitigation:
Apply the latest security patches and updates to the system.