CVE-2017-8335 is a stack buffer overflow vulnerability affecting Securifi Almond, Almond+, and Almond 2015 devices running firmware AL-R096. The vulnerability arises from insufficient string length checks on the "mssid_1" POST parameter when setting wireless network names, allowing an attacker to send an oversized payload. This payload overflows a buffer during the processing of a request to view the Wi-Fi network name, enabling control over the $ra register and arbitrary code execution. Rated with a CVSS v3.0 score of 8.0 (High), this vulnerability has a network attack vector and low attack complexity, requiring user interaction (UI:R). A successful exploit could lead to complete compromise of the device (C:H, I:H, A:H). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
al-r096CPE matchmatch criteria | cpe:2.3:o:securifi:almond_2015_firmware:al-r096:*:*:*:*:*:*:* | ||
al-r096CPE matchmatch criteria | cpe:2.3:o:securifi:almond\+firmware:al-r096:*:*:*:*:*:*:* | ||
al-r096CPE matchmatch criteria | cpe:2.3:o:securifi:almond_firmware:al-r096:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.