{ "schema_version": "1.4.0", "id": "GHSA-jqqc-8vpc-2wjv", "modified": "2025-04-24T15:30:43Z", "published": "2022-12-06T00:30:15Z", "aliases": [ "CVE-2022-40918" ], "details": "Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to these links > http://thiscomputer.com/ > https://www.bostoncyber.org/ > https://medium.com/@meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40918" }, { "type": "WEB", "url": "https://1af95112-6fd8-4c8f-8bd6-c47f8ef7b77a.filesusr.com/ugd/c1f861_2bf7a43eda204c87ae7de972f4494590.pdf" }, { "type": "WEB", "url": "https://1af95112-6fd8-4c8f-8bd6-c47f8ef7b77a.filesusr.com/ugd/c1f861_51eb0d33d5764efc93e9d5f19c306950.pdf" }, { "type": "WEB", "url": "https://medium.com/%40meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368" }, { "type": "WEB", "url": "https://medium.com/@meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368" } ], "database_specific": { "cwe_ids": [ "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-12-06T00:15:00Z" } }