Intelbras RX1500
cpe:2.3:h:intelbras:rx_1500:*:*:*:*:*:*:*, +1 more
- <= 2.2.17
An integer overflow vulnerability has been identified in the Intelbras RX1500 Router, specifically in versions through 2.2.17. The issue arises in the websReadEvent function, which improperly handles the 'command' field of the HTTP header. This mismanagement allows the array to exceed its boundaries, potentially overwriting other fields and leading to arbitrary file writing. In more severe cases, this vulnerability could be exploited for arbitrary command execution.
Exploitation of this vulnerability could result in arbitrary file writing and, in severe cases, arbitrary command execution on the router.
To reproduce this vulnerability, send a POST request to the '/cgi-bin/ExportSettings.sh' endpoint. Include a 'command-2' header with a payload that exceeds the typical length, such as a long string of characters. This will trigger the integer overflow by causing the array to cross its boundary and overwrite adjacent fields.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.