Vulnerabilities > CVE-2018-4029 - Out-of-bounds Write vulnerability in Anker-In Roav Dashcam A1 Firmware 1.9
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an unlimited and arbitrary write to memory, resulting in code execution.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Common Weakness Enumeration (CWE)
Talos
id | TALOS-2018-0701 |
last seen | 2019-05-29 |
published | 2019-05-13 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0701 |
title | Novatek NT9665X HFS Recv buffer overflow code execution vulnerability |