NETGEAR R6700v3 Password Reset /...

- AV AC AU C I A
发布: 2020-06-25
修订: 2024-12-11

This document describes a stack overflow vulnerability that was found in October, 2019 and presented in the Pwn2Own Mobile 2019 competition in November 2019. The vulnerability is present in the UPNP daemon (/usr/sbin/upnpd), running on NETGEAR R6700v3 router with firmware versions V1.0.4.82_10.0.57 and V1.0.4.84_10.0.58. It allows for an unauthenticated reset of the root password and then spawns a telnetd to remotely access the account.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息