Netis NC63 固件 V3.0.0.3327 及更早版本存在栈缓冲区溢出漏洞,该漏洞允许未经身份验证的远程攻击者通过向 netis.cgi 中的 ipFilterList=mod 动作提供超长的 destHost 参数,从而覆盖已保存的栈状态。攻击者可以利用宽度不限的 sscanf 转换,在验证身份之前将用户提供的输入复制到固定大小的栈缓冲区中,从而在具有 root 权限的 Boa Web 服务器执行 CGI 环境时,实现以 root 身份进行的远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Netis Systems | NC63 | ≤ 3.0.0.3327 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Netis Systems | NC63 | 0 ~ 3.0.0.3327 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet