vendor:
SB5101 Hax0rware
by:
Dillon Beresford
8,8
CVSS
HIGH
Remote Exploit
119
CWE
Product Name: SB5101 Hax0rware
Affected Version From: Hax0rware 1.1 R30
Affected Version To: Hax0rware 1.1 R39
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
Motorola SB5101 Hax0rware Rajko HttpD Remote Exploit PoC
If an unauthenticated user or attacker sends any number of bytes greater than 1 to port 80 without a proper request line, such as, [ GET /somepath/file.cgi ] the http daemon triggers a crash on thread at 0x8054b9ac Rajko HttpD.
Mitigation:
The developer of Hax0rware said he has used the modem's local ip to bind to the webserver to prevent attackers from triggering the vuln.