VYPR

CWE-121

Stack-based Buffer Overflow

VariantDraftLikelihood: High

Description

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (3,602)

page 15 of 181
  • CVE-2025-44884CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

  • CVE-2025-45513CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.

  • CVE-2025-3714CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.02

    The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2025-3711CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.02

    The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2025-3710CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.02

    The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2025-45790CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.

  • CVE-2025-45789CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.

  • CVE-2025-45788CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.

  • CVE-2025-45787CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.

  • CVE-2025-45841CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.

  • CVE-2025-44899CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.

  • CVE-2025-45429CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

  • CVE-2025-45428CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-45427CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-22900CriApr 15, 2025
    risk 0.64cvss 9.8epss 0.01

    Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

  • CVE-2024-54809CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an…

  • CVE-2024-54808CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code…

  • CVE-2025-29135CriMar 24, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.

  • CVE-2025-29100CriMar 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.

  • CVE-2025-2621CriMar 22, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has…