CVE-2024-57480 Details
Description
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
A buffer overflow vulnerability has been identified in the H3C N12 router, specifically in the V100R005 version. This vulnerability arises from inadequate length verification in the access point (AP) configuration function. Attackers exploiting this issue can cause the device to crash or execute arbitrary commands by sending a POST request to the '/bin/webs' endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/XiaoCurry/16213a4d68f95f17cd0fc2cd07e78a90 | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| h3c n12 firmware | 100r005 |
CPE
Remediation
| |
| h3c n12 | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 27, 2025 | Initial Analysis | [email protected] |
| Mar 18, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 16, 2025 | CVE Modified | CISA-ADP |
| Jan 14, 2025 | New CVE Received | [email protected] |