vendor:
NRVMini2
by:
Jacob Baines
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: NRVMini2
Affected Version From: 3.8.2000
Affected Version To: 3.8.2000
Patch Exists: NO
Related CWE:
CPE: a:nuuo:nvrmini2:3.8.0
Platforms Tested: Ubuntu and OSX
2018
NUUO NVRMini2 3.8 – ‘cgi_system’ Buffer Overflow (Enable Telnet)
A stack buffer overflow exists in the cgi_system binary. The error occurs due to lack of bounds checking on the PHPSESSID value before and when it is passed to sprintf in order to generate the session id file name. As written, this exploit enables Telnet. Executes a command via the stack buffer overflow in cookie parsing. The command is executed via 'system' as root.
Mitigation:
Update to a version above 3.8.0