cve/2015/CVE-2015-2797.md

19 lines
804 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2015-2797](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2797)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.
### POC
#### Reference
- https://www.exploit-db.com/exploits/36577/
- https://www.exploit-db.com/exploits/37170/
#### Github
- https://github.com/echel0nn/having-fun-with-qiling