TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This may result in remote code execution or denial of service. The issue is in the binary rtspd (in /sbin) when parsing a long "Authorization: Basic" RTSP header.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://payatu.com/blog/munawwar/trendNet-wireless-camera-buffer-overflow-vulnerability | third party advisory exploit |