Web Hack List

Collected research

Belkin Buffer Overflow via Web

From 0-day to exploit – Buffer overflow in Belkin N750 (CVE-2014-1635)

An unauthenticated POST to the Belkin N750 guest network web interface overflows a strcpy buffer and overwrites two adjacent heap variables, one that forces a CGI to run and one holding the CGI name passed to popen. Because popen invokes a shell, the attacker injects arbitrary commands and gains a root shell on the router.

Record

Document
From 0-day to exploit – Buffer overflow in Belkin N750 (CVE-2014-1635)
Researcher
Marco Vaz
Published by
labs.integrity.pt
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Marco Vaz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .