CVE-2024-45413

HIGH

ZTE Routers - Authenticated Stack-based Buffer Overflow in HTTPD rsa_decrypt Function

Title source: llm
STIX 2.1

Description

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking its length. An authenticated attacker can get RCE as root by exploiting this vulnerability.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0038
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Published Sep 16, 2024
Tracked Since Feb 18, 2026