CVE-2020-36949
7.5Raimersoft · TapinRadio
TapinRadio 2.13.7 contains a denial of service vulnerability in the application proxy settings that allows attackers to crash the program by overflowing input fields.
Executive summary
A heap-based buffer overflow vulnerability in Raimersoft TapinRadio 2.13.7 allows an attacker to cause a persistent denial of service condition requiring application reinstallation.
Vulnerability
The application fails to properly validate the length of input provided to the proxy username and address fields. An attacker can supply an excessively large buffer, triggering a resource exhaustion state that renders the application permanently unresponsive.
Business impact
Successful exploitation of this vulnerability results in a complete denial of service for the affected application. Because the crash state persists even after restarting the software, the business impact includes potential loss of productivity and the operational overhead required to uninstall and reinstall the software to restore functionality. While the CVSS score is 7.5, the impact is localized to the specific endpoint rather than the wider network environment.
Remediation
Immediate Action: There is no official patch available for this vulnerability at this time. Administrators should restrict access to the application settings to authorized users only to prevent local exploitation.
Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or attempts to access configuration files that deviate from standard administrative behavior.
Compensating Controls: Implement endpoint security policies that limit the ability of non-administrative users to modify software configurations or proxy settings.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit-DB entry 49206.
Analyst recommendation
Given the lack of a vendor-supplied patch, organizations relying on TapinRadio 2.13.7 should treat this as a high-risk configuration issue. Ensure that the application is installed only on systems where users are restricted from modifying core settings, and evaluate alternative software if persistent denial of service risks cannot be managed through administrative controls.
Sources
Originally found and disclosed by Ismael Nava, per the CVE Program record.
- ExploitDB-49206 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: TapinRadio 2.13.7 - Denial of Service Third-party advisory