CVE Vulnerabilities

CVE-2019-19506

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 25, 2020 | Modified: Jul 08, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the homeplugd process. By sending a specially crafted UDP packet, an attacker could exploit this vulnerability to cause the device to reboot.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Pa6_firmware Tendacn 1.0.1.21 (including) 1.0.1.21 (including)

References