UTT Aggressive HiPER 810G Buffer Overflow Vulnerability in formGroupConfig Function Allowing Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in the UTT Aggressive HiPER 810G router, specifically in firmware versions through v3v1.7.7-171114. The issue arises in the notes parameter of the formGroupConfig function, where improper input handling allows attackers to manipulate memory, leading to a denial-of-service condition.
Impact
Exploitation of this vulnerability causes a denial-of-service condition, likely by causing the device to crash or become unresponsive.
Reproduction
The vulnerability can be reproduced by sending a crafted POST request to the /goform/formGroupConfig endpoint. The request must include a 'notes' parameter with a payload designed to overflow the buffer. This can be done by using a large amount of data that exceeds the buffer's capacity, taking advantage of the 'strcpy' function's lack of bounds checking.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
