Planet FW-WGS-804HPT Stack Overflow Vulnerability in web_aaa_loginAuthlistEdit Function

Vulnerability

A stack overflow vulnerability has been identified in the Planet FW-WGS-804HPT Ethernet switch, specifically in version 1.305b241111. The issue arises in the web_aaa_loginAuthlistEdit function, where theauthName parameter is improperly handled, leading to a buffer overflow. This vulnerability allows for control flow hijacking by overflowing the stack and overwriting return addresses.

Impact

Exploitation of this vulnerability causes a stack overflow, allowing attackers to overwrite the return address and hijack the control flow of the application. This could potentially lead to arbitrary code execution.

Reproduction

The vulnerability can be reproduced by sending a POST request to the dispatcher.cgi with a crafted authName parameter. The value of authName should be a long string of characters, sufficient to overflow the stack buffer. This can be done using a tool like QEMU to emulate the router environment and simulate the request.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.