VYPR
Unrated severityNVD Advisory· Published Mar 1, 2023· Updated Mar 10, 2025

CVE-2023-24118

CVE-2023-24118

Description

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack overflow vulnerability in the WifiBasicSet function of Jensen Eagle 1200AC router allows remote unauthenticated code execution via a crafted security parameter.

Vulnerability

The Jensen of Scandinavia Eagle 1200AC router, firmware version V15.03.06.33_en, contains a stack overflow vulnerability in the /goform/WifiBasicSet handler. The security parameter is copied into a fixed-size stack buffer without proper bounds checking, allowing an attacker to overwrite adjacent memory. [1]

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP POST request to the router's web interface with an overly long security parameter. No authentication or user interaction is required, and the vulnerability is reachable from the LAN or WAN if the web interface is exposed.

Impact

Successful exploitation results in stack-based buffer overflow, which can lead to arbitrary code execution in the context of the root user. This gives the attacker full control over the device, including the ability to modify configuration, intercept traffic, or launch further attacks against internal networks. Denial of service is also possible.

Mitigation

As of the publication date (2023-03-01), no official fix has been released. Users should monitor the vendor's support page [1] for firmware updates. Until a patch is available, restrict access to the router's web interface to trusted networks only and disable remote administration if not required.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.