Libtor maintains firmware for a narrowly scoped line of industrial networking devices, the LBT-T300/T390 series, which appear to serve specialized embedded-control or remote-access roles. The vendor's recurring vulnerability profile centers on memory-safety issues endemic to firmware codebases, chiefly stack-based buffer overflows, classic buffer-copy flaws, and out-of-bounds writes that reflect insufficient input validation in low-level network handlers. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libtor over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27572HIGH LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a Denia | Mar 1, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-27570HIGH LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a | Mar 1, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-27571HIGH LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the makeCurRemoteApList function. This vulnerability allows attackers to cause a D | Mar 1, 2024 | 7.5 | 19 | NO | NO |
CVE-2024-27569MEDIUM LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a Denial of | Mar 1, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-27568MEDIUM LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a Denial | Mar 1, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-27567MEDIUM LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause a | Mar 1, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libtor.
Media articles that mention a CVE ID that affects a product developed by Libtor — matched by CVE ID, not by vendor name.