VYPR
Unrated severityNVD Advisory· Published Mar 1, 2023· Updated Mar 7, 2025

CVE-2023-24127

CVE-2023-24127

Description

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack overflow in Jensen Eagle 1200AC router's wepkey1 parameter allows remote code execution via crafted request.

Vulnerability

The Jensen Eagle 1200AC router running firmware version V15.03.06.33_en [1] contains a stack-based buffer overflow vulnerability in the /goform/WifiBasicSet handler. The wepkey1 parameter is copied into a fixed-size stack buffer without proper bounds checking, enabling an attacker to overflow the buffer and overwrite adjacent memory.

Exploitation

An attacker with network access to the router's web management interface can send a crafted HTTP POST request to /goform/WifiBasicSet with an overly long wepkey1 parameter. Authentication is likely required to access the form, but once authenticated, the overflow can be triggered remotely. No user interaction beyond authenticating is needed.

Impact

Successful exploitation of the stack overflow can lead to denial of service (crash of the web server) or potentially arbitrary code execution in the context of the device. Given the nature of embedded routers, code execution could allow an attacker to gain full control of the device, leading to network compromise.

Mitigation

As of the publication date, no firmware update or patch has been released by the vendor [1]. Users are advised to restrict access to the router's management interface to trusted networks only, disable remote management if not needed, and monitor for future security updates.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.