VYPR
High severity7.5NVD Advisory· Published Aug 19, 2021· Updated Jun 17, 2026

CVE-2021-36762

CVE-2021-36762

Description

An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:hcc-embedded:nichestack:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hcc-embedded:nichestack:*:*:*:*:*:*:*:*range: <4.3
    • (no CPE)range: <=4.3
  • HCC Embedded/NicheStackdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.