目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2022-30114 PoC — Fastweb FASTGate 缓冲区错误漏洞

来源
关联漏洞
标题: Fastweb FASTGate 缓冲区错误漏洞 (CVE-2022-30114)
Description:Fastweb FASTGate是意大利Fastweb公司的一款调制解调器。 Fastweb FASTGate MediaAccess FGA2130FWB 18.3.n.0482_FW_230_FGA2130 固件版本和 DGA4131FWB 18.3.n.0462_FW_261_DGA4131 及之前固件版本存在安全漏洞,该漏洞源于允许远程攻击者通过精心设计的 HTTP 请求重启设备 , 导致 DoS。
介绍
# Fastweb FastGate *'cmproxy'* buffer overflow (CVE-2022-30114)

## Introduction
This script is a Proof of Concept (PoC) of CVE-2022-30114 and causes a reboot of **[Fastweb FastGate](https://www.fastweb.it/myfastweb/assistenza/guide/FASTGate/)** home routers, both GPON and VDSL2 version.

CVE-2022-30114 is a ***heap-based* buffer overflow** in the *'cmproxy'* executable, a program which handles HTTP requests through a Lighttpd FastCGI webserver listening on TCP port 8888.  A specially crafted HTTP request allows a remote attacked to crash the executable and reboot the device, causing a Denial of Service.

### Affected devices
* **Technicolor MediaAccess FGA2130FWB** (GPON) - Version 18.3.n.0482_FW_233_FGA2130 and below 
* **Technicolor MediaAccess DGA4131FWB** (VDSL2) - Version 18.3.n.0482_FW_264_DGA4131 and below


## Vulnerabilty 
The devices are vulnerable to a *heap-based* buffer overflow, caused by the lack of validation of the length of the '*Authorization*' HTTP header value on the web service exposed on **TCP port 8888**. The service is exposed on both the WAN and the LAN interfaces of the device[^1].

[^1]: WAN access was disabled as a compensative control after the first disclosure to Fastweb. As of writing, the service is still exposed on the internal LAN.

A remote, unauthenticated attacker, sending a string longer than 100 bytes in the '*Authorization*' HTTP header, causes an overflow in a pre-allocated buffer in the *'.bss'* memory section of an executable file called *'cmproxy'* which handles HTTP requests sent on the mentioned service above via FastCGI protocol.

This allows to overwrite the process's heap memory, causing the process to become corrupted and crash on the first memory allocation. It's worth noting that the C library version used (GNU C Library - glibc v2.24) contains protection measures to detect heap corruption but it is not excluded, however, that by deepening the analysis it would be possible to overwrite heap structures and achieve code execution.

See [Blog Post](https://str0ng4le.github.io) for details.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →