An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.talosintelligence.com/reports/TALOS-2016-0237/ | exploit third party advisory mitigation |