H3C N12 V100R005 Buffer Overflow Vulnerability in MAC Address Update Function
Vulnerability
A buffer overflow vulnerability has been identified in the H3C N12 V100R005 router model. This vulnerability arises from the MAC address update function's failure to properly verify the length of incoming data. Attackers who exploit this vulnerability can cause the device to crash or execute arbitrary commands by sending a specially crafted POST request to the device's web interface.
Impact
Exploitation of this vulnerability can lead to a denial of service, causing the device to crash, or allow for arbitrary command execution on the device.
Reproduction
To reproduce this vulnerability, send a POST request to the '/bin/webs' endpoint with a crafted MAC address that exceeds the expected length. The lack of proper length validation will trigger the buffer overflow, potentially leading to a crash or unauthorized command execution on the device.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
