Netis WF2880
cpe:2.3:h:netis-systems:wf2880:*:*:*:*:*:*:*, +1 more
- v2.1.40207
A buffer overflow vulnerability has been identified in the Netis WF2880 router, specifically in the v2.1.40207 firmware. The issue occurs in the FUN_00471994 function of the cgitest.cgi file. Attackers can exploit this vulnerability by manipulating the wl_base_set value in the payload, potentially causing the device to crash and leading to a Denial-of-Service (DoS) condition.
Exploitation of this vulnerability causes a crash of the affected program, leading to a Denial-of-Service condition.
The vulnerability can be reproduced by sending a payload with a crafted wl_base_set value to the cgitest.cgi script on a Netis WF2880 router running firmware v2.1.40207. This can be done by using QEMU to emulate the router's environment, after extracting the firmware with binwalk.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.