UTT 进取 520W Buffer Overflow Vulnerability in ConfigExceptMSN Function
Vulnerability
A buffer overflow vulnerability has been identified in the UTT 进取 520W router, specifically in the firmware version 1.7.7-180627. The issue arises in the ConfigExceptMSN function, where the strcpy function is used to copy data without proper size validation, allowing for remote exploitation. This vulnerability has been publicly disclosed and could be used to execute a denial-of-service attack.
Impact
Exploitation of this vulnerability leads to a buffer overflow, which can commonly be used to execute arbitrary code or cause a denial-of-service condition by crashing the device.
Reproduction
The vulnerability can be reproduced by sending a POST request to the /goform/ConfigExceptMSN endpoint. The request must include a payload that exceeds the buffer size, effectively causing the overflow. This can be done by manipulating the 'remark' parameter to include a large amount of data.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
