Published: 15/07/2020 Updated: 21/07/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions before 5.4).

Vulnerability Trend

Recent Articles

Critical Bugs in Utilities VPNs Could Cause Physical Damage
Threatpost • Tara Seals • 29 Jul 2020

Remote code-execution vulnerabilities in virtual private network (VPN) products could impact the physical functioning of critical infrastructure in the oil and gas, water and electric utilities space, according to researchers.
Researchers at Claroty found that VPNs used to provide remote access to operational technology (OT) networks in industrial systems are vulnerable to an array of security bugs, which could give an attacker direct access to field devices and cause physical damage or sh...

Industrial VPN vulnerabilities put critical infrastructure at risk
BleepingComputer • Ionut Ilascu • 28 Jul 2020

Security researchers analyzing popular remote access solutions used for industrial control systems (ICS) found multiple vulnerabilities that could let unauthenticated attackers execute arbitrary code and breach the environment.
The flaws are in virtual private network (VPN) implementations  and adversaries could exploit them cause physical damage by connecting to field devices and programmable logic controllers (PLCs).