Vulnerabilities > CVE-2018-4023 - Out-of-bounds Write vulnerability in Anker-In Roav Dashcam A1 Firmware 1.9
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Common Weakness Enumeration (CWE)
Talos
id | TALOS-2018-0695 |
last seen | 2019-05-29 |
published | 2019-05-13 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0695 |
title | Novatek NT9665X XML_UploadFile path overflow code execution vulnerability |