Skip to content

Latest commit

 

History

History
28 lines (14 loc) · 1006 Bytes

27.md

File metadata and controls

28 lines (14 loc) · 1006 Bytes

TOTOLINK X2000R_V2(V2.0.0-B20230727.10434) router buffer overflow vulnerability

Information

Vendor:http://totolink.net/

Firmware:https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/259/ids/36.html

Affected Version

V2.0.0-B20230727.1043

image

Detail

sub_447E18 (handle function of formMeshUploadConfig) of /bin/boa in firmware has buffer overflow vulnerability.

image

image

Parameter "submit-url" is read from HTTP request into $v0_7, then copied to variable data_48e234, which locates on BSS segment. When "submit-url" has excessive length, this would result a buffer overflow.

PoC

I'm not able to provide full exploit for this vulnerability due to legal reasons.