CVE-2019-6963
Last modified
CVE-2019-6963 is a vulnerability of currently unknown severity. A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rdkcentral | Rdkb Ccsppandm | rdkb-20181217-1 |
References
- https://dojo.bullguard.com/dojo-by-bullguard/blog/the-gateway-is-wide-openThird Party Advisory
- https://dojo.bullguard.com/dojo-by-bullguard/blog/the-gateway-is-wide-openThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6963?
How severe is CVE-2019-6963?
How do I fix CVE-2019-6963?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6956An issue was discovered in Freeware Advanced Audio Decoder 2…7.1
- CVE-2019-6957A recently discovered security vulnerability affects all Bos…9.8
- CVE-2019-6958A recently discovered security vulnerability affects all Bos…9.1
- CVE-2019-6960An issue was discovered in GitLab Community and Enterprise E…9.8
- CVE-2019-6961Incorrect access control in actionHandlerUtility.php in the …
- CVE-2019-6962A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-…
- CVE-2019-6964A heap-based buffer over-read in Service_SetParamStringValue…
- CVE-2019-6965An XSS issue was discovered in i-doit Open 1.12 via the src/…
- CVE-2019-6966An issue was discovered in Bento4 1.5.1-628. The AP4_ElstAto…
- CVE-2019-6967AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
- CVE-2019-6968The web interface of the D-Link DVA-5592 20180823 is vulnera…6.1
- CVE-2019-6969The web interface of the D-Link DVA-5592 20180823 is vulnera…7.5
Are you affected by CVE-2019-6963?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
