A CWE-126 “Buffer Over-read” was discovered affecting the...
High severity
Unreviewed
Published
Feb 13, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Feb 13, 2025
Published to the GitHub Advisory Database
Feb 13, 2025
A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability in order to leak valid authentication tokens from the process memory associated to users currently logged to the system and bypass the authentication mechanism.
References