In SunGrow WiNet-SV200.001.00.P027 and earlier versions,...
High severity
Unreviewed
Published
Jan 25, 2025
to the GitHub Advisory Database
•
Updated Jan 27, 2025
Description
Published by the National Vulnerability Database
Jan 24, 2025
Published to the GitHub Advisory Database
Jan 25, 2025
Last updated
Jan 27, 2025
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.
References