Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the string is concatenated to the HTML body.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://hub.digi.com/support/products/infrastructure-management/digi-passport/ | product vendor advisory |
https://github.com/X-C3LL/PoC-CVEs/blob/master/CVE-2022-26952%20%26%20CVE-2022-26953/readme.md | third party advisory exploit |
https://hub.digi.com/dp/path=/support/asset/digi-passport-1.5.2-firmware-release-notes/ | release notes vendor advisory |