漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Linksys WRT120N tmUnblock.cgi Stack-Based Buffer Overflow Admin Password Reset
Vulnerability Description
A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router. The vulnerability is triggered by sending a specially crafted HTTP POST request with an overly long TM_Block_URL parameter to the endpoint. By exploiting this flaw, an unauthenticated remote attacker can overwrite memory in a controlled manner, enabling them to temporarily reset the administrator password of the device to a blank value. This grants unauthorized access to the router’s web management interface without requiring valid credentials.
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
Linksys WRT120N 安全漏洞
Vulnerability Description
Linksys WRT120N是美国Linksys公司的一款路由器。 Linksys WRT120N存在安全漏洞,该漏洞源于tmUnblock.cgi端点边界检查不当,可能导致栈缓冲区溢出和密码重置。
CVSS Information
N/A
Vulnerability Type
N/A