CVE-2020-37171 PUBLISHED

TapinRadio 2.12.3 - 'username' Denial of Service

Assigner: VulnCheck
Reserved: 06.02.2026 Published: 06.02.2026 Updated: 06.02.2026

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor Raimersoft
Product TapinRadio
Versions
  • Version 2.12.3 is affected

Credits

  • chuyreds finder

References

Problem Types

  • Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE