A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrary code as the root user.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://blog.securityevaluators.com/remotely-exploiting-iot-pet-feeders-21013562aea3 | third party advisory exploit |