vendor:
CDE-30364
by:
Matias Mingorance Svensson
7,5
CVSS
HIGH
Insufficient bounds checking of data supplied in HTTP GET requests
20
CWE
Product Name: CDE-30364
Affected Version From: 3.1.0.8-ONO
Affected Version To: 3.1.0.8-ONO
Patch Exists: NO
Related CWE: N/A
CPE: h:hitron:cde-30364
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Hitron Technologies CDE-30364
2013
Router ONO Hitron CDE-30364 – Denial Of Service(80 port)
Hitron Technologies CDE-30364 is a famous ONO Router. The Hitron Technologies CDE-30364's web interface (listening on tcp/ip port 80), have a problem to insufficient bounds checking of data supplied in HTTP GET requests. An attacker can send a malicious HTTP GET request with a large number of A characters to the router, causing the router to crash and become unavailable.
Mitigation:
Ensure that all data supplied in HTTP GET requests is properly validated and sanitized.