UTT 进取 512W Buffer Overflow Vulnerability in ConfigExceptMSN Function
Vulnerability
A buffer overflow vulnerability has been identified in the UTT 进取 512W router, specifically in versions through 1.7.7-171114. The issue arises in the ConfigExceptMSN function, where improper handling of the 'remark' parameter by the 'strcpy' function creates the potential for buffer overflow. This vulnerability can be exploited remotely, leading to buffer overflow attacks and possible denial-of-service conditions.
Impact
Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition on the device.
Reproduction
The vulnerability can be reproduced by sending a POST request to the '/goform/ConfigExceptMSN' endpoint. The request must include a 'remark' parameter with a payload that exceeds the buffer size, effectively causing a buffer overflow. This can be done by manipulating the 'msnNumber' and 'remark' fields in the request.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
