Skip to content

AyresWiFiManager 2.3.2

Choose a tag to compare

@IdefixRC IdefixRC released this 29 Sep 13:35
· 31 commits to main since this release

Overview

AyresWiFiManager 2.3.2 is a security patch release of the IdefixRC fork. It fixes an HTML and script injection in the captive portal's network list. Everyone using the portal should update.

This fork tracks ayresnet/AyresWiFiManager. The fix is offered upstream as ayresnet/AyresWiFiManager#11.

Security fix

  • Scanned SSIDs are shown as text, not HTML. The portal built its network list with innerHTML and inserted each SSID unescaped. SSIDs come from any access point in radio range, so a nearby network whose name contained HTML could run script inside the setup page while someone was configuring the device. The maximum SSID length of 32 bytes is enough for that. The script ran with the page's own access, so it could call /save (point the device at a different network) or /erase.
  • The fix builds the SSID and signal elements with textContent. It applies to the built-in page in src/AWM_html_gz.h, to data/index.html, and to data/index_en.html, which isn't served by default but can be uploaded as a custom page.
  • Verified in a browser against a mock /scan returning an SSID with an event-handler payload: before the fix the handler ran; after it, the name is shown literally and nothing executes.

Compatibility

  • Framework: Arduino
  • Platform: ESP32
  • Arduino-ESP32 core: 2.x and 3.x
  • Dependency: ArduinoJson ^6.21.2

Upgrade Notes

2.3.2 is a drop-in replacement for 2.3.1. There are no API changes.

lib_deps =
  https://github.com/IdefixRC/AyresWiFiManager.git#2.3.2

If your project uploads its own portal pages to LittleFS, updating the library is not enough, because those pages override the built-in ones. Check your index.html for code that inserts SSIDs with innerHTML, apply the same fix, and upload the file system again.

Thank you to Daniel Salgado and AyresNet for AyresWiFiManager, and to everyone using and testing it.