Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NHIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
3.5.21.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.5.21.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.5.21.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.5.21.0 (semver) before 3.5.22.20
affected
Default status
unaffected
3.5.21.0 (semver) before 3.5.22.20
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
0.0.0 (semver) before 4.21.0.0
affected
Default status
unaffected
4.15.0.0 (semver) before 4.21.0.0
affected
Description
The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.
Problem types
CWE-1284 Improper Validation of Specified Quantity in Input
Product status
3.5.21.0 (semver) before 3.5.22.20
3.5.21.0 (semver) before 3.5.22.20
3.5.21.0 (semver) before 3.5.22.20
3.5.21.0 (semver) before 3.5.22.20
3.5.21.0 (semver) before 3.5.22.20
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
0.0.0 (semver) before 4.21.0.0
4.15.0.0 (semver) before 4.21.0.0
References
www.certvde.com/en/advisories/VDE-2026-057/