Collected research
Belkin Buffer Overflow via Web
From 0-day to exploit – Buffer overflow in Belkin N750 (CVE-2014-1635)
An unauthenticated POST to the Belkin N750 guest network web interface overflows a strcpy buffer and overwrites two adjacent heap variables, one that forces a CGI to run and one holding the CGI name passed to popen. Because popen invokes a shell, the attacker injects arbitrary commands and gains a root shell on the router.
Record
- Document
- From 0-day to exploit – Buffer overflow in Belkin N750 (CVE-2014-1635)
- Researcher
- Marco Vaz
- Published by
- labs.integrity.pt
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Marco Vaz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .