Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header, causing the array to cross the boundary and overwrite other fields in the array.
History

Wed, 20 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Intelbras
Intelbras rx 1500
Intelbras rx 1500 Firmware
CPEs cpe:2.3:h:intelbras:rx_1500:-:*:*:*:*:*:*:*
cpe:2.3:o:intelbras:rx_1500_firmware:*:*:*:*:*:*:*:*
Vendors & Products Intelbras
Intelbras rx 1500
Intelbras rx 1500 Firmware

Tue, 08 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 14:45:00 +0000

Type Values Removed Values Added
Description Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header, causing the array to cross the boundary and overwrite other fields in the array.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-07-01T00:00:00.000Z

Updated: 2025-07-08T15:42:43.267Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50404

cve-icon Vulnrichment

Updated: 2025-07-01T14:44:02.567Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-01T15:15:26.043

Modified: 2025-08-20T17:05:58.403

Link: CVE-2025-50404

cve-icon Redhat

No data.