← Vulnerability feed

Vulnerability record · CVE-2019-9501 · published 3 February 2020

CVE-2019-9501: Synology router manager heap-based buffer overflow vulnerability

Synology · Router Manager

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

8.8 CVSS 3.1 High EPSS 3.1% · top 12.6% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 8.3
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html ExploitThird Party Advisory
https://kb.cert.org/vuls/id/166939/ Third Party AdvisoryUS Government Resource
https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html ExploitThird Party Advisory
https://kb.cert.org/vuls/id/166939/ Third Party AdvisoryUS Government Resource

Track CVE-2019-9501 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-27655Synology router manager improper privilege management vulnerabilityImproper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i…EPSS 1.8%9.8CVE-2023-32956Synology router manager vulnerabilityImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager …EPSS 1.5%9.8CVE-2023-0077Synology router manager vulnerabilityInteger overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote att…EPSS 0.95%9.8CVE-2020-27654Synology router manager improper privilege management vulnerabilityImproper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands…EPSS 4.7%9.8CVE-2018-1160Netatalk dsi_opensess.c out-of-bounds write allows remote code executionNetatalk before 3.1.12 fails to bounds-check attacker-controlled data in dsi_opensess.c, producing an out-of-bounds write. A remote unauthenticated a…EPSS 87%analysed9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed9.0CVE-2020-27649Synology router manager improper certificate validation vulnerabilityImproper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers…EPSS 0.72%8.8CVE-2023-41738Synology router manager vulnerabilityImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synolog…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-9501), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.