CVE-2022-30114
A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP request, causing DoS.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- fastweb/fastgate vdsl2 dga4131fwb firmware · fastweb/fastgate gpon fga2130fwb firmware
- Source
- cve@mitre.org
References
- https://str0ng4le.github.io/jekyll/update/2023/05/12/fastgate-bof-cve-2022-30114/Exploit, Technical Description, Third Party Advisory
- https://www.fastweb.it/myfastweb/assistenza/guide/FASTGate/
- https://str0ng4le.github.io/jekyll/update/2023/05/12/fastgate-bof-cve-2022-30114/Exploit, Technical Description, Third Party Advisory
- https://www.fastweb.it/myfastweb/assistenza/guide/FASTGate/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.