Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password
Published Jun 17, 2019
7.8
HIGHCVSS 3.0
EPSS 0.73%
Description
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is installed on the device and an attacker who can provide the right payload can execute code on the user's system directly. Any breach of this system can allow an attacker to get access to all the data that the user has access too. The application uses a dynamic link library(DLL) called "avilib.dll" which is used by the application to send binary packets to the device that allow to control the device. One such action that the DLL provides is change password in the function "sendchangepass" which allows a user to change the Wi-Fi password on the device. This function calls a sub function "sub_75876EA0" at address 0x7587857C. The function determines which action to execute based on the parameters sent to it. The "sendchangepass" passes the datastring as the second argument which is the password we enter in the textbox and integer 2 as first argument. The rest of the 3 arguments are set to 0. The function "sub_75876EA0" at address 0x75876F19 uses the first argument received and to determine which block to jump to. Since the argument passed is 2, it jumps to 0x7587718C and proceeds from there to address 0x758771C2 which calculates the length of the data string passed as the first parameter.This length and the first argument are then passed to the address 0x7587726F which calls a memmove function which uses a stack address as the destination where the password typed by us is passed as the source and length calculated above is passed as the number of bytes to copy which leads to a stack overflow.
Affected products
No data.
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.73% (0.00735) | 52.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.73% (0.00735) | 49.44th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.24% (0.00241) | 45.45th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00098) | 42.48th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.10% (0.00098) | 40.88th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00082) | 33.25th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.36% (0.01365) | 71.56th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.36% (0.01365) | 45.07th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.46% (0.01458) | 32.87th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.46% (0.01458) | 0.00th | v1 |
References (3)
- http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf x_refsource_MISCExploitThird Party Advisory
- https://seclists.org/bugtraq/2019/Jun/8 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf | x_refsource_MISCExploitThird Party Advisory | |
| https://seclists.org/bugtraq/2019/Jun/8 | mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.