VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,626)

page 120 of 182
  • CVE-2025-60549HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.

  • CVE-2025-60547HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.

  • CVE-2025-60572HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.

  • CVE-2025-60571HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS.

  • CVE-2025-60570HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.

  • CVE-2025-60569HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.

  • CVE-2025-60568HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.

  • CVE-2025-60342HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60341HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60334HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60333HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60331HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-11678HigOct 20, 2025
    risk 0.49cvss epss 0.00

    Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id…

  • CVE-2025-20350HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due…

  • CVE-2025-61577HigOct 9, 2025
    risk 0.49cvss 7.5epss 0.05

    D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60663HigOct 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.

  • CVE-2025-60662HigOct 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.

  • CVE-2025-60660HigOct 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.

  • CVE-2023-28760HigOct 2, 2025
    risk 0.49cvss 7.5epss 0.03

    TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field to minidlnad. The attacker obtains the ability to modify files.db, and that can be used to reach a stack-based buffer overflow…

  • CVE-2025-59251HigSep 24, 2025
    risk 0.49cvss 7.6epss 0.00

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability