PT-2026-53104 · Unknown · Xiaozhi-Esp32
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
xiaozhi-esp32 versions prior to 2.2.7
Description
A remote denial of service can be triggered through the manipulation of the
session id argument. This issue resides within the Application::GetInstance() function located in the main/protocols/mqtt protocol.cc file of the MQTT Goodbye Handler component. The attack complexity is high and exploitability is considered difficult.Recommendations
Apply patch e182471f8c5a22434346bd98da34d3b66c8c8b3e to resolve the issue.
Exploit
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xiaozhi-Esp32