Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-19945

uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-19945
  • Openwrt » Openwrt » Version: 18.06.0
    cpe:2.3:o:openwrt:openwrt:18.06.0
  • Openwrt » Openwrt » Version: 18.06.1
    cpe:2.3:o:openwrt:openwrt:18.06.1
  • Openwrt » Openwrt » Version: 18.06.2
    cpe:2.3:o:openwrt:openwrt:18.06.2
  • Openwrt » Openwrt » Version: 18.06.3
    cpe:2.3:o:openwrt:openwrt:18.06.3
  • Openwrt » Openwrt » Version: 18.06.4
    cpe:2.3:o:openwrt:openwrt:18.06.4
  • Openwrt » Openwrt » Version: 18.06.5
    cpe:2.3:o:openwrt:openwrt:18.06.5
  • Openwrt » Openwrt » Version: 19.07.0
    cpe:2.3:o:openwrt:openwrt:19.07.0


Contact Us

Shodan ® - All rights reserved