Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-45460 Details

Description

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-787Out-of-bounds Write[email protected]
CWE-787Out-of-bounds WriteCISA-ADP

Affected Products

ProductVersions
xiongmaitech nbd6808t-pl firmware
4.02.r11.c7431119.12001.130000.00000

CPE

  • cpe:2.3:o:xiongmaitech:nbd6808t-pl_firmware:4.02.r11.c7431119.12001.130000.00000:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
xiongmaitech nbd6808t-pl
All versions

CPE

  • cpe:2.3:h:xiongmaitech:nbd6808t-pl:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
xiongmaitech mbd6304t firmware
4.02.r11.00000117.10001.131900.00000

CPE

  • cpe:2.3:o:xiongmaitech:mbd6304t_firmware:4.02.r11.00000117.10001.131900.00000:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
xiongmaitech mbd6304t
All versions

CPE

  • cpe:2.3:h:xiongmaitech:mbd6304t:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-45460
NVD Published Date:
Mar 28, 2023
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-45460 Details - Not Deferred