UTT HiPER 1250GW Buffer Overflow Vulnerability in Remote Control Function
Vulnerability
A stack-based buffer overflow vulnerability has been identified in the UTT HiPER 1250GW router, affecting firmware versions through 3.2.7-210907-180535. The vulnerability arises in the '/goform/formRemoteControl' file, where the 'Profile' parameter is manipulated. This exploitation can be performed remotely by an authenticated user, leading to memory overwriting, device crashes, and a denial-of-service condition.
Impact
Exploitation of this vulnerability causes a stack-based buffer overflow, allowing for memory overwriting that can disrupt normal device operation, potentially leading to arbitrary code execution.
Reproduction
To reproduce this vulnerability, send a POST request to '/goform/formRemoteControl' with an excessively long 'Profile' parameter. The request must include Digest authentication as an admin user.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
