VYPR
Unrated severityNVD Advisory· Published Sep 13, 2004· Updated Apr 16, 2026

CVE-2004-1680

CVE-2004-1680

Description

application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.

Affected products

6
  • Pingtel/Xpressa6 versions
    cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:h:pingtel:xpressa:1.2.7.4:*:*:*:*:*:*:*
    • cpe:2.3:h:pingtel:xpressa:1.2.8:*:*:*:*:*:*:*
    • cpe:2.3:h:pingtel:xpressa:2.0:*:*:*:*:*:*:*
    • cpe:2.3:h:pingtel:xpressa:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:h:pingtel:xpressa:2.1.11.24:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.