CVE-2023-50239 describes two stack-based buffer overflow vulnerabilities in the Realtek rtl819x Jungle SDK v3.4.11, specifically within the boa set_RadvdInterfaceParam functionality, affecting various Realtek and Level1 products. These vulnerabilities, triggered by a specially crafted 'interfacename' parameter in network requests, carry a CVSS score of 7.2 (HIGH) due to their network-based attack vector, low complexity, and potential for remote code execution, as well as high impact on confidentiality, integrity, and availability. Despite the high severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.4.11CPE matchmatch criteria | cpe:2.3:a:realtek:rtl819x_jungle_software_development_kit:3.4.11:*:*:*:*:*:*:* | ||
rer4_a_v3411b_2t2r_lev_09_170623CPE matchmatch criteria | cpe:2.3:o:level1:wbr-6013_firmware:rer4_a_v3411b_2t2r_lev_09_170623:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.