CVE-2022-26953

HIGH

Digi Passport Firmware <1.5.1 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the string is concatenated to the HTML body.

Scores

CVSS v3 7.5
EPSS 0.0066
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (1)
digi/passport_firmware < 1.5.1.1
Published Apr 06, 2022
Tracked Since Feb 18, 2026