Wavlink AC3000 Buffer Overflow Vulnerability in adm.cgi rep_as_router() Function
Vulnerability
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the rep_as_router() function. This vulnerability, present in version M33A8.V5030.210505, allows for a stack-based buffer overflow when a specially crafted HTTP request is sent. The issue can be triggered by an authenticated user.
Impact
Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the device.
Reproduction
To reproduce this vulnerability, an authenticated user must send an HTTP POST request to the adm.cgi file with the page parameter set to 'wzdrepeater'. The request must include a crafted 'wl_rep_ssid2g' parameter that exceeds 160 bytes. This will cause the router to overwrite the return address of the function, leading to a segmentation fault and potential code execution.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
