On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.
2019-02-21T19:29:00.570
2024-11-21T04:50:45.637
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:C
10.0
8.5
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | netis-systems | wf2411_firmware | 2.1.36123 | Yes |
| Hardware | netis-systems | wf2411 | - | No |
| Operating System | netis-systems | wf2880_firmware | 2.1.36123 | Yes |
| Hardware | netis-systems | wf2880 | - | No |