An issue was discovered on GL.iNet devices before 3.216....
Critical severity
Unreviewed
Published
May 11, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 11, 2023
Published to the GitHub Advisory Database
May 11, 2023
Last updated
Apr 4, 2024
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
References