VYPR
Unrated severityNVD Advisory· Published Mar 1, 2023· Updated Mar 18, 2025

CVE-2023-24124

CVE-2023-24124

Description

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack overflow in Jensen Eagle 1200AC router's WifiBasicSet via wrlEn parameter allows remote code execution or denial of service.

Vulnerability

A stack overflow vulnerability exists in the wrlEn parameter of the /goform/WifiBasicSet endpoint in Jensen of Scandinavia Eagle 1200AC firmware version V15.03.06.33_en. The vulnerability is triggered when processing a specially crafted HTTP request to the vulnerable parameter, leading to a stack-based buffer overflow.

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP POST request to the /goform/WifiBasicSet endpoint with an overly long wrlEn parameter. No authentication is required if the endpoint is exposed, but typically the router's web interface is accessible only from the local network. The attacker does not need prior access to the device.

Impact

Successful exploitation could lead to denial of service due to stack overflow, or potentially arbitrary code execution with the privileges of the web server process, which typically runs as root on embedded routers. This could allow full compromise of the device.

Mitigation

As of the publication date (2023-03-01), no official patch or firmware update has been released by Jensen of Scandinavia. Users should restrict access to the router's web interface to trusted networks and monitor for vendor updates. The device may be end-of-life; consider replacing it if no fix is provided.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.