Netis WF2780
cpe:2.3:h:netis-systems:wf2780:*:*:*:*:*:*:*, +1 more
- v2.2.35445
A null pointer dereference vulnerability has been identified in the Netis WF2780 router, specifically in the firmware version 2.2.35445. The issue arises in the FUN_0048a728 function within the cgitest.cgi file. Attackers can exploit this vulnerability by manipulating the CONTENT_LENGTH environment variable, leading to a program crash and causing a denial-of-service (DoS) condition.
Exploitation of this vulnerability causes a null pointer dereference, leading to a program crash and a denial-of-service condition.
The vulnerability can be reproduced by setting the CONTENT_LENGTH environment variable to a negative value, which triggers the null pointer dereference in the cgitest.cgi file.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.