PT-2026-68138 · Domoticz · Domoticz
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Domoticz (affected versions not specified)
Description
The
MochadTCP::MatchLine() function in the hardware/MochadTCP.cpp file fails to perform length checks when copying data from the m mochadbuffer (up to 1028 bytes) into a fixed 50-byte stack buffer named tempRFSECbuf using strcpy(). This occurs across three code branches for DS10A, KR10A, and MS10A device types. A local network attacker can send a crafted packet to the Mochad TCP bridge on port 1099, which requires no authentication, to overflow tempRFSECbuf and corrupt the worker thread stack.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Domoticz