UTT Aggressive HiPER 810G Buffer Overflow Vulnerability in ConfigAdvideo Function Allowing Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in the UTT Aggressive HiPER 810G router, specifically in firmware versions through v3v1.7.7-171114. The issue arises in the ConfigAdvideo function, where the timestart parameter lacks proper boundary checks. This vulnerability can be exploited by sending a crafted input, leading to a denial-of-service condition.
Impact
Exploitation of this vulnerability causes a denial-of-service condition, likely by causing the device to crash or become unresponsive.
Reproduction
The vulnerability can be reproduced by sending a POST request to the /goform/ConfigAdvideo endpoint. The request must include a 'timestart' parameter with a payload that exceeds the buffer limit, effectively causing a buffer overflow. This can be done by manipulating the Content-Length header to accommodate the oversized 'timestart' value.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
