VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 119 of 182
  • CVE-2025-63460HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63469HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63468HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63467HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63466HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-61498HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.

  • CVE-2025-60566HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.

  • CVE-2025-60565HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.

  • CVE-2025-60564HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.

  • CVE-2025-60563HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.

  • CVE-2025-60562HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.

  • CVE-2025-60561HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.

  • CVE-2025-60559HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.

  • CVE-2025-60558HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formVirtualServ.

  • CVE-2025-60557HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.

  • CVE-2025-60556HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.

  • CVE-2025-60555HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

  • CVE-2025-60552HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.

  • CVE-2025-60551HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.

  • CVE-2025-60550HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.