Netis NC63 固件 V3.0.0.3327 版本存在一个基于栈的缓冲区溢出漏洞。未认证的远程攻击者可通过向 /bin/netis.cgi 中的登录处理函数提交过大的 Base64 编码密码,覆盖保存的栈状态。攻击者可利用自定义 Base64 解码器在对固定大小栈缓冲区进行输出长度验证方面的缺失,实现远程代码执行,并获得 root 权限,因为 Boa Web 服务器以 root 权限运行 CGI 环境。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Netis Systems | NC63 | 0 ~ 3.0.0.3327 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet