Yifanwireless manufactures a narrow line of wireless networking devices centered on the YF325 product family and its firmware, which despite modest volume sits prominently in the vulnerability landscape, suggesting concentrated exposure in deployed units. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses—out-of-bounds writes, stack-based buffer overflows, integer overflows, and classic buffer overflows—that are characteristic of firmware codebases with limited memory protection and validation discipline. The presence of active debug code compounds the attack surface by potentially exposing additional vectors for manipulation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yifanwireless over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32645CRITICAL A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication | Oct 11, 2023 | 9.8 | 60 | NO | NO |
CVE-2023-35056CRITICAL A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An atta | Oct 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-35055CRITICAL A buffer overflow vulnerability exists in the httpd next_page functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An atta | Oct 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-34346CRITICAL A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command exe | Oct 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-35966CRITICAL Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buf | Oct 11, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-32632CRITICAL A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command exec | Oct 11, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-24479CRITICAL An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command e | Oct 11, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-35967CRITICAL Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead | Oct 11, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-34426CRITICAL A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-bas | Oct 11, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-34365CRITICAL A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a bu | Oct 11, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yifanwireless.
Media articles that mention a CVE ID that affects a product developed by Yifanwireless — matched by CVE ID, not by vendor name.