Vulnerability Description
Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers to execute arbitrary code via (1) a long temp attribute in a yweather:condition element in a forecastrss file that is processed by the checkWeather function; the (2) WeatherCity or (3) WeatherDegree variable to the detectWeather function; unspecified input to the (4) UpnpAddRunRLQoS, (5) UpnpDeleteRunRLQoS, or (6) UpnpDeletePortCheckType function; or (7) the SET COUNTRY udps command.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | N300 Netusb Nbg-419N Firmware | 1.00\(bfq_6\)c0 |
| Zyxel | N300 Netusb Nbg-419N | - |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/939260US Government Resource
- http://www.kb.cert.org/vuls/id/939260US Government Resource
FAQ
What is CVE-2014-0355?
CVE-2014-0355 is a vulnerability with a CVSS score of 7.9 (HIGH). Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers to execute arbitrary code via (1) a long temp attr...
How severe is CVE-2014-0355?
CVE-2014-0355 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0355?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel N300 Netusb Nbg-419N Firmware, Zyxel N300 Netusb Nbg-419N.