UTT HiPER 1200GW Buffer Overflow Vulnerability in Remote Control Function
Vulnerability
A buffer overflow vulnerability has been identified in the UTT HiPER 1200GW router, affecting firmware versions through 2.5.3-170306. The vulnerability arises in the remote control function, specifically within the '/goform/formRemoteControl' endpoint. This issue can be exploited remotely, leading to potential buffer overflow attacks and denial-of-service conditions.
Impact
Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition.
Reproduction
The vulnerability can be reproduced by sending a POST request to the '/goform/formRemoteControl' endpoint. The request must include a 'Profile' parameter filled with a payload that exceeds the buffer size, triggering the overflow. The request should be sent with Digest authentication, using 'admin' as the username.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
