UTT Aggressive HiPER 810G Buffer Overflow Vulnerability in formTaskEdit Function Allowing Denial-of-Service
Vulnerability
A buffer overflow vulnerability has been identified in the UTT Aggressive HiPER 810G router, specifically in firmware versions through v3v1.7.7-171114. The issue arises in the selDateType parameter of the formTaskEdit function, where lack of proper boundary checks allows for crafted inputs to be processed. This vulnerability can be exploited to cause a denial-of-service condition by triggering a buffer overflow.
Impact
Exploitation of this vulnerability leads to a denial-of-service condition, causing the device to become unresponsive or unavailable.
Reproduction
To reproduce this vulnerability, send a POST request to the /goform/formTaskEdit endpoint. Include a crafted payload in the selDateType parameter that exceeds the buffer limit, effectively causing a buffer overflow. The request must be authorized using Digest authentication with valid credentials.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
