Skip to main content
HIGH

CVE-2019-19505

CVSS v3

8.8

HIGH

EPSS Score

3.3 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Technical details

Published
2020-06-25

Frequently asked questions

What is CVE-2019-19505?

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted hostname, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Is CVE-2019-19505 actively exploited?

Active exploitation of CVE-2019-19505 has not been confirmed. The EPSS score is 3.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-19505?

CVE-2019-19505 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-19505 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key