A heap-based buffer overflow in cosadhcpv4dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module.
{
"extracted_events": [
{
"introduced": "rdkb-20181217-1"
},
{
"last_affected": "rdkb-20181217-1"
}
],
"cpe": "cpe:2.3:a:rdkcentral:rdkb_ccsppandm:rdkb-20181217-1:*:*:*:*:*:*:*",
"source": "CPE_STRING"
}