A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://dojo.bullguard.com/dojo-by-bullguard/blog/the-gateway-is-wide-open | third party advisory |