Draft in the CWE catalog · 3 CVEs mapped
The product does not properly handle when a particular element is not completely specified.
⚡ Just a few incomplete SOAP requests can send the wscserver crashing down like a house of cards—no login required! Think of it as a restaurant where a customer sends back their meal with a vague complaint. The kitchen shuts down entirely, and the staff can’t serve anyone else until the manager comes in and resets the whole system. 🙈 This means an attacker could crash the service, leaving users stranded and needing a full device reboot to get things running again. Imagine the chaos—no access, unhappy users, and a big mess to clean up!
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.
The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard.