exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Netgear WG602v4 Saved Password Stack Overflow

Netgear WG602v4 Saved Password Stack Overflow
Posted May 30, 2010
Authored by Cristofaro Mune | Site icysilence.org

The Netgear WG602v4 suffers from a saved password stack overflow vulnerability.

tags | advisory, overflow
SHA-256 | 43880da74509f3b5b9103626adbc669276aacebb54cf3a964bf94e7a2dffa3a0

Netgear WG602v4 Saved Password Stack Overflow

Change Mirror Download
Security Advisory

IS-2010-001 - Netgear WG602v4 Saved Pass Stack Overflow



Advisory Information
--------------------
Published:
2010-05-30

Updated:
2009-05-30

Manufacturer: Netgear
Model: WG602v4
Firmware version: V1.1.0 (Europe)



Vulnerability Details
---------------------
Class:
Buffer Overflow

Code Execution:
Yes

Public References:
Not Assigned

Successfully tested on:
Netgear WG602v4 loaded with firmware version 1.1.0 (Europe)
Other models and/or firmware versions may be also affected.

Summary:
A stack based buffer overflow can be triggered by choosing an overly
long admin password.

Details:
A buffer overflow condition can be triggered during the authentication
process to the device web interface.
Such process is handled by function auth_authorize(), where password
saved in flash memory is used for validating submitted credentials, and
is copied into a fixed size buffer on the stack, without performing any
length check.
Buffer overflow can be triggered by saving an admin password longer than
128 characters and occurs at each authentication attempt before the
submitted credentials are validated, potentially allowing for
unauthenticated remote exploitation.
But, valid credentials are required in order to change administrator
password and save it in flash memory, hence, for vulnerability exploitation.
Password can be changed via a dedicated web page on the management
interface: client side restrictions present on on the password lenght
can be easily bypassed by an attacker.

Impact:
Remote code execution with root level privileges.

Solutions & Workaround:
Not available


Additional Information
---------------------
Available at http://www.icysilence.org

Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close