在 Comfast CF-N1-S 2.6.0.1 版本中发现了一个漏洞。受影响的是 Web 管理组件中的 /cgi-bin/mbox-config?method=SET§ion=ntp_timezone 文件的 sub_41AD7C 函数。对参数 timestr/ntp_client_enabled 的操作会导致基于栈的缓冲区溢出。攻击者可以远程发起攻击。该漏洞的利用代码(exploit)已经公开,可以被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet