Vulnerability Details CVE-2024-40084
A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via exceptionally long HTTP methods or paths.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.6%
CVSS Severity
CVSS v3 Score 9.6
Products affected by CVE-2024-40084
-
cpe:2.3:h:viloliving:vilo_5:-
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.123
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.129
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.133
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.166
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.176
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.186
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.206
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.209
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.0.84
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.13
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.19
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.26
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.33
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.16.1.9
-
cpe:2.3:o:viloliving:vilo_5_firmware:5.6.0.38